Last seen May 30, 2025

Linux Zero-Day Vulnerability Discovered Using Frontier AI

A remotely exploitable zero-day vulnerability, CVE-2025-37899, has been discovered in the Linux kernel's Server Message Block (SMB) protocol using OpenAI's o3 model. This critical flaw is identified as a use-after-free bug in the SMB 'logoff' command handler, allowing an object to be freed while still accessible by another thread.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

A remotely exploitable zero-day vulnerability, CVE-2025-37899, has been discovered in the Linux kernel's Server Message Block (SMB) protocol using OpenAI's o3 model. This critical flaw is identified as a use-after-free bug in the SMB 'logoff' command handler, allowing an object to be freed while still accessible by another thread.

Why This Matters

Publisher reporting describes a security event affecting openai. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether Linux is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

May 30, 2025 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

OpenAILinux kernelSMB ProtocolServer Message Block (SMB) protocolDay Vulnerability DiscoveredLinux Zero

Authoritative Intelligence

CVE CVE-2025-37899 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.

CVE-2025-37899: 3 public repository references found.

SeanHeelan/o3_finds_cve-2025-37899

Public GitHub reference

Artefacts for blog post on finding CVE-2025-37899 with o3

354 stars

Open repository
vett3x/SMB-LINUX-CVE-2025-37899

Public GitHub reference

GitHub repository for an AI tooling project

0 stars

Open repository
ccss17/o3_finds_cve-2025-37899

Public GitHub reference

Artefacts for blog post on finding CVE-2025-37899 with o3

0 stars

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    May 30, 2025 05:30

    BugSkan first recorded this incident.

  • Linux Zero-Day Vulnerability Discovered Using Frontier AI - Bank Info Security
    May 30, 2025 05:30

    bankinfosecurity.com · Vulnerability

Sources

Linux Zero-Day Vulnerability Discovered Using Frontier AI - Bank Info Security

bankinfosecurity.com · May 30, 2025 05:30

A remotely exploitable zero-day vulnerability, CVE-2025-37899, has been discovered in the Linux kernel's Server Message Block (SMB) protocol using OpenAI's o3 model. This critical flaw is identified as a use-after-free bug in the SMB 'logoff' command handler, allowing an object to be freed while still accessible by another thread.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence