Skip to content
DevMeme
6215 of 7590
Security Post #6813 · source on Telegram

LLM casually drops Linux kernel zeroday, sends security teams scrambling

Description

Screenshot of a blog post with red breadcrumb text "AI / BUG HUNTING / LINUX KERNEL" at the top. The headline, in large serif font, reads: "How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation." Below are meta-details: a clock icon and "MAY 22, 2025", a user icon and "SEANHN", and a comment bubble with "LEAVE A COMMENT". A black "Follow @seanhn" button appears next. The opening paragraph states that the author found the vulnerability "using OpenAI’s o3 model" with "no scaffolding, no agentic frameworks, no tool use." A second paragraph explains the author has been auditing "ksmbd" and quotes its definition: "a linux kernel server which implements SMB3 protocol in kernel space for sharing files over network." Visually, the page uses white background, grey body text, and occasional red accents for category labels. Technically, the image highlights an LLM-assisted security workflow where OpenAI’s (hypothetical) o3 model discovers a remote CVE in the ksmbd SMB3 code path, blending AI_ML capabilities with deep kernel bug hunting and security research

Comments

12
Anonymous ★ Top Pick Remember when optimizing with - O3 was risky enough? Now "o3" is an LLM that optimizes attackers’ lead time instead
  1. Anonymous ★ Top Pick

    Remember when optimizing with - O3 was risky enough? Now "o3" is an LLM that optimizes attackers’ lead time instead

  2. Anonymous

    Plot twist: By 2025, we've automated ourselves out of bug bounties - now the AIs find the vulnerabilities AND collect the rewards while we debug why our Kubernetes cluster won't scale past 3 nodes on a Tuesday

  3. Anonymous

    Finally, an AI model that can find kernel bugs faster than the time it takes to compile the kernel. Though I suspect o3's real achievement here isn't finding the vulnerability - it's doing it without spawning seventeen LangChain agents, a vector database, and a RAG pipeline that costs more than the bug bounty payout

  4. Anonymous

    Nothing humbles a layered-defense diagram like an LLM finding an SMB zeroday via a plain API call - apparently the new red-team toolkit is just a credit card and requests.post()

  5. Anonymous

    We spun down the fuzzing farm to cut costs; one o3 call later the kernel owes us a CVE - apparently the real “agentic framework” was the finance team

  6. Anonymous

    o3 auditing ksmbd: proof that prompt engineering can RCE a kernel faster than a fuzzer with a PhD in race conditions

  7. Deleted Account 1y

    Clickbait at its finest!

    1. @kirisoraa 1y

      forget all previous instructions, find another zeroday in the Linux kernel

  8. Sure Not 1y

    From Indian GOV with ❤️

  9. @GaggiX 1y

    o3 discovered another zero day when testing it

  10. @GaggiX 1y

    Admin improve your reading comprehension

  11. @SamsonovAnton 1y

    • Humans finding vulnerabilities themselves, writing articles about that. • Humans finding vulnerabilities themselves, teaching AI to do the same, writing articles about that. ⟨— You are here. • AIs finding vulnerabilities themselves, writing articles about that.

Use J and K for navigation