We are also experiencing this issue with 2.4.40 when we try to create a replica from the primary.
our current workaround is to exclude the pwdPolicy objectclass:
olcSyncrepl: {0}rid=000 provider=ldap://127.0.0.1:389 type=refreshAndPersist retry="5 5 300 +" searchbase="dc=chi,dc=braintreepayments,dc=com" attrs="*,+" filter="(!(objectClass=pwdPolicy))" bindmethod=simple binddn="cn=admin,dc=chi,dc=braintreepayments,dc=com" credentials=openldaptest schemachecking=off