---
id: CVE-2021-46993
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  sched: Fix out-of-bound access in uclamp

  Util-clamp places tasks in different buckets based on their clamp values
  for performance reasons
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  sched: Fix out-of-bound access in uclamp

  Util-clamp places tasks in different buckets based on their clamp values
  for performance reasons. However, the size of buckets…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.3, < 5.4.120'
  - 'linux_kernel >= 5.5, < 5.10.38'
  - 'linux_kernel >= 5.11, < 5.11.22'
  - 'linux_kernel >= 5.12, < 5.12.5'
patched:
  - linux_kernel 5.12.5
published: '2024-02-28'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-46993'
references:
  - url: 'https://git.kernel.org/stable/c/3da3f804b82a0a382d523a21acf4cf3bb35f936d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/42ee47c7e3569d9a0e2cb5053c496d97d380472f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/687f523c134b7f0bd040ee1230f6d17990d54172'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6d2f8909a5fabb73fe2a63918117943986c39b6c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f7347c85490b92dd144fa1fba9e1eca501656ab3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3da3f804b82a0a382d523a21acf4cf3bb35f936d'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/42ee47c7e3569d9a0e2cb5053c496d97d380472f'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/687f523c134b7f0bd040ee1230f6d17990d54172'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/6d2f8909a5fabb73fe2a63918117943986c39b6c'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/f7347c85490b92dd144fa1fba9e1eca501656ab3'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00241
epssPercentile: 0.15564
ingestedAt: '2026-08-04T10:39:38.942Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

sched: Fix out-of-bound access in uclamp

Util-clamp places tasks in different buckets based on their clamp values
for performance reasons. However, the size of buckets is currently
computed using a rounding division, which can lead to an off-by-one
error in some configurations.

For instance, with 20 buckets, the bucket size will be 1024/20=51. A
task with a clamp of 1024 will be mapped to bucket id 1024/51=20. Sadly,
correct indexes are in range [0,19], hence leading to an out of bound
memory access.

Clamp the bucket id to fix the issue.

## Affected

- `linux_kernel >= 5.3, < 5.4.120`
- `linux_kernel >= 5.5, < 5.10.38`
- `linux_kernel >= 5.11, < 5.11.22`
- `linux_kernel >= 5.12, < 5.12.5`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.12.5`
