Vulnerability record · CVE-2024-3933 · published 27 May 2024
CVE-2024-3933: Eclipse openj9 out-of-bounds read vulnerability
Eclipse · Openj9
In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.
Description
In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/eclipse/omr/pull/7275 | Issue TrackingPatch |
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/21 | Issue TrackingVendor Advisory |
| https://github.com/eclipse/omr/pull/7275 | Issue TrackingPatch |
| https://gitlab.eclipse.org/security/cve-assignement/-/issues/21 | Issue TrackingVendor Advisory |
Track CVE-2024-3933 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-3933), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.