Stack-Based Buffer Overflow in Eclipse OpenJ9 and OpenJDK
CVE-2025-4447

7HIGH

Key Information:

Status
Vendor
CVE Published:
9 May 2025

Summary

A stack-based buffer overflow vulnerability exists in Eclipse OpenJ9 versions up to 0.51 when utilized with OpenJDK version 8. This flaw occurs due to the manipulation of a file on disk that is accessed during the JVM startup process, potentially leading to unexpected behavior or exploitation during runtime. Developers and system administrators should ensure their systems are updated to mitigate the risk posed by this vulnerability.

Affected Version(s)

OpenJ9 0.8.0 <= 0.49.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-4447 : Stack-Based Buffer Overflow in Eclipse OpenJ9 and OpenJDK | SecurityVulnerability.io