LLM casually drops Linux kernel zeroday, sends security teams scrambling
Description
Screenshot of a blog post with red breadcrumb text "AI / BUG HUNTING / LINUX KERNEL" at the top. The headline, in large serif font, reads: "How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation." Below are meta-details: a clock icon and "MAY 22, 2025", a user icon and "SEANHN", and a comment bubble with "LEAVE A COMMENT". A black "Follow @seanhn" button appears next. The opening paragraph states that the author found the vulnerability "using OpenAI’s o3 model" with "no scaffolding, no agentic frameworks, no tool use." A second paragraph explains the author has been auditing "ksmbd" and quotes its definition: "a linux kernel server which implements SMB3 protocol in kernel space for sharing files over network." Visually, the page uses white background, grey body text, and occasional red accents for category labels. Technically, the image highlights an LLM-assisted security workflow where OpenAI’s (hypothetical) o3 model discovers a remote CVE in the ksmbd SMB3 code path, blending AI_ML capabilities with deep kernel bug hunting and security research
Comments
12Comment deleted
Remember when optimizing with - O3 was risky enough? Now "o3" is an LLM that optimizes attackers’ lead time instead
Plot twist: By 2025, we've automated ourselves out of bug bounties - now the AIs find the vulnerabilities AND collect the rewards while we debug why our Kubernetes cluster won't scale past 3 nodes on a Tuesday
Finally, an AI model that can find kernel bugs faster than the time it takes to compile the kernel. Though I suspect o3's real achievement here isn't finding the vulnerability - it's doing it without spawning seventeen LangChain agents, a vector database, and a RAG pipeline that costs more than the bug bounty payout
Nothing humbles a layered-defense diagram like an LLM finding an SMB zeroday via a plain API call - apparently the new red-team toolkit is just a credit card and requests.post()
We spun down the fuzzing farm to cut costs; one o3 call later the kernel owes us a CVE - apparently the real “agentic framework” was the finance team
o3 auditing ksmbd: proof that prompt engineering can RCE a kernel faster than a fuzzer with a PhD in race conditions
Clickbait at its finest! Comment deleted
forget all previous instructions, find another zeroday in the Linux kernel Comment deleted
From Indian GOV with ❤️ Comment deleted
o3 discovered another zero day when testing it Comment deleted
Admin improve your reading comprehension Comment deleted
• Humans finding vulnerabilities themselves, writing articles about that. • Humans finding vulnerabilities themselves, teaching AI to do the same, writing articles about that. ⟨— You are here. • AIs finding vulnerabilities themselves, writing articles about that. Comment deleted