YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0043

Register entry

Linux ksmbd use-after-free in session logoff, found with OpenAI o3 by Sean Heelan

CVE
CVE-2025-37899
Project
Linux kernel
Component
ksmbd, smb2_session_logoff
Finder
OpenAI o3, run by Sean Heelan
Model
o3
Autonomy
model given about 12,000 lines of SMB handlers and prompted for use-after-free; the researcher validated the result
Evidence tier
Claim outside the record
Assigner
Linux
Severity
8.8 High (CVSS 3.1)
Bounty
None published
Confidence
CONFIRMED

What happened

"ksmbd: fix use-after-free in session logoff", published 20 May 2025. Heelan's account is that o3 surfaced the concurrency flaw in smb2_session_logoff when given the SMB command handlers and asked to look for use-after-free.

Credit as recorded: credits array empty (normal for Linux CNA records); attribution in the researcher's own account. Date basis: datePublished.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026