Executive Summary

Informations
Name CVE-2021-46993 First vendor Publication 2024-02-28
Vendor Cve Last vendor Modification 2024-12-24

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Overall CVSS Score 7.1
Base Score 7.1 Environmental Score 7.1
impact SubScore 5.2 Temporal Score 7.1
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact None Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

sched: Fix out-of-bound access in uclamp

Util-clamp places tasks in different buckets based on their clamp values for performance reasons. However, the size of buckets is currently computed using a rounding division, which can lead to an off-by-one error in some configurations.

For instance, with 20 buckets, the bucket size will be 1024/20=51. A task with a clamp of 1024 will be mapped to bucket id 1024/51=20. Sadly, correct indexes are in range [0,19], hence leading to an out of bound memory access.

Clamp the bucket id to fix the issue.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46993

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-125 Out-of-bounds Read

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Os 3460

Sources (Detail)

https://git.kernel.org/stable/c/3da3f804b82a0a382d523a21acf4cf3bb35f936d
https://git.kernel.org/stable/c/42ee47c7e3569d9a0e2cb5053c496d97d380472f
https://git.kernel.org/stable/c/687f523c134b7f0bd040ee1230f6d17990d54172
https://git.kernel.org/stable/c/6d2f8909a5fabb73fe2a63918117943986c39b6c
https://git.kernel.org/stable/c/f7347c85490b92dd144fa1fba9e1eca501656ab3
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Date Informations
2025-07-15 01:52:43
  • Multiple Updates
2025-07-14 12:16:20
  • Multiple Updates
2025-06-26 01:51:34
  • Multiple Updates
2025-06-25 12:15:48
  • Multiple Updates
2025-06-24 01:56:02
  • Multiple Updates
2025-03-29 02:57:01
  • Multiple Updates
2025-03-28 13:27:23
  • Multiple Updates
2025-03-28 02:41:59
  • Multiple Updates
2025-03-18 02:49:50
  • Multiple Updates
2025-03-14 02:39:54
  • Multiple Updates
2025-01-08 02:34:44
  • Multiple Updates
2025-01-07 02:34:21
  • Multiple Updates
2024-12-24 17:20:51
  • Multiple Updates
2024-11-25 09:26:41
  • Multiple Updates
2024-02-28 17:27:37
  • Multiple Updates
2024-02-28 13:27:31
  • First insertion