← Vulnerability feed

Vulnerability record · CVE-2024-3933 · published 27 May 2024

CVE-2024-3933: Eclipse openj9 out-of-bounds read vulnerability

Eclipse · Openj9

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.

7.3 CVSS 3.1 High EPSS 0.21% · top 90.0% CWE-125 · Out-of-bounds readCWE-787 · Out-of-bounds write
7.3CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-41035Eclipse openj9 execution with unnecessary privileges vulnerabilityIn Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.EPSS 1.8%9.8CVE-2020-27221Eclipse openj9 stack-based buffer overflow vulnerabilityIn Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are …EPSS 1.5%9.8CVE-2019-11772Eclipse openj9 out-of-bounds write vulnerabilityIn Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that …EPSS 2.1%9.8CVE-2018-12547Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…EPSS 2.7%9.8CVE-2018-12549Eclipse openj9 improper input validation vulnerabilityIn Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when acceleratin…EPSS 2.3%9.8CVE-2018-12548Eclipse openj9 memory buffer overflow vulnerabilityIn OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p…EPSS 1.1%9.1CVE-2023-2597Eclipse openj9 classic buffer overflow vulnerabilityIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a strin…EPSS 0.43%9.1CVE-2019-17631Eclipse openj9 improper authorization vulnerabilityFrom Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2024-3933), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.