Tools AI-Found Vulnerability Register aifv-0044
Register entry
Linux ksmbd dangling pointer in krb_authenticate, the benchmark bug Sean Heelan ran o3 against
- CVE
- CVE-2025-37778
- Project
- Linux kernel
- Component
- ksmbd, krb_authenticate
- Finder
- OpenAI o3, run by Sean Heelan
- Model
- o3
- Autonomy
- a known bug used as the benchmark for the o3 run; the model rediscovered it
- Evidence tier
- Claim outside the record
- Assigner
- Linux
- Severity
- 9.8 Critical (CVSS 3.1)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
"ksmbd: Fix dangling pointer in krb_authenticate", published 1 May 2025. The row is the control inside Heelan's experiment: a bug already found by a person, which o3 rediscovered before it went on to CVE-2025-37899.
Credit as recorded: credits array empty; attribution in the researcher's own account. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
- Sean Heelan, how I used o3 to find CVE-2025-37899sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-378…
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026