CVE-2024-3933: Eclipse Open J9 With -Xgc:concurrentScavenge on IBM Z, could write/read outside of a buffer

Published May 27, 2024
·
Updated

Eclipse Openj9 could allow a local authenticated attacker to bypass security restrictions, caused by the failure to restrict access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. By sending a specially crafted request, an attacker could exploit this vulnerability to gain read and write to addresses beyond the end of the array range.

Other sources

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z platform with hardware and software support for guarded storage [1], could allow access to a buffer with an incorrect length value when executing an arraycopy sequence while the Concurrent Scavenge Garbage Collection cycle is active and the source and destination memory regions for arraycopy overlap. This allows read and write to addresses beyond the end of the array range.

MITRE

Affected Software

2 affected components
Eclipse Openj9>=0.13.0<0.44.0
IBM DB2 Recovery Expert for LUW<=5.5 IF 2

Event History

May 27, 2024
CVE Published
via MITRE·06:08 AM
Data Sourced
via MITRE·06:08 AM
DescriptionSeverityWeakness
Feb 5, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-3933?

CVE-2024-3933 is classified as a medium severity vulnerability due to the potential for local authenticated attackers to bypass security restrictions.

2

How do I fix CVE-2024-3933?

To mitigate CVE-2024-3933, updating to the fixed versions of Eclipse Openj9 or IBM Storage Protect Backup-Archive Client is recommended.

3

Who is affected by CVE-2024-3933?

CVE-2024-3933 affects users of Eclipse Openj9 versions from 0.13.0 to 0.44.0 and IBM Storage Protect Backup-Archive Client versions up to 8.1.23.0.

4

What kind of attack does CVE-2024-3933 facilitate?

CVE-2024-3933 allows local authenticated attackers to potentially bypass security restrictions through improper buffer access.

5

Is there any workaround for CVE-2024-3933?

There are no specific workarounds available for CVE-2024-3933; updating is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203