CVE-2024-3933
Last modified
CVE-2024-3933 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Openj9 | >= 0.13.0, < 0.44.0 |
References
- https://github.com/eclipse/omr/pull/7275Issue Tracking, Patch
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/21Issue Tracking, Vendor Advisory
- https://github.com/eclipse/omr/pull/7275Issue Tracking, Patch
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/21Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3933?
How severe is CVE-2024-3933?
How do I fix CVE-2024-3933?
Are you affected by CVE-2024-3933?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
