Linux Zero-Day Vulnerability Discovered Using Frontier AI
A remotely exploitable zero-day vulnerability, CVE-2025-37899, has been discovered in the Linux kernel's Server Message Block (SMB) protocol using OpenAI's o3 model. This critical flaw is identified as a use-after-free bug in the SMB 'logoff' command handler, allowing an object to be freed while still accessible by another thread.
What Happened
A remotely exploitable zero-day vulnerability, CVE-2025-37899, has been discovered in the Linux kernel's Server Message Block (SMB) protocol using OpenAI's o3 model. This critical flaw is identified as a use-after-free bug in the SMB 'logoff' command handler, allowing an object to be freed while still accessible by another thread.
Why This Matters
Publisher reporting describes a security event affecting openai. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether Linux is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
May 30, 2025 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.
CVE-2025-37899: 3 public repository references found.
Public GitHub reference
Artefacts for blog post on finding CVE-2025-37899 with o3
354 stars
Open repositoryPublic GitHub reference
GitHub repository for an AI tooling project
0 stars
Open repositoryPublic GitHub reference
Artefacts for blog post on finding CVE-2025-37899 with o3
0 stars
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
May 30, 2025 05:30BugSkan first recorded this incident.
-
Linux Zero-Day Vulnerability Discovered Using Frontier AI - Bank Info Security
May 30, 2025 05:30bankinfosecurity.com · Vulnerability
Sources
bankinfosecurity.com · May 30, 2025 05:30
A remotely exploitable zero-day vulnerability, CVE-2025-37899, has been discovered in the Linux kernel's Server Message Block (SMB) protocol using OpenAI's o3 model. This critical flaw is identified as a use-after-free bug in the SMB 'logoff' command handler, allowing an object to be freed while still accessible by another thread.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.