OpenAI's o3 AI Model Uncovers Zero-Day Vulnerability in Linux Kernel

Reviewed byNidhi Govil

2 Sources

A cybersecurity researcher used OpenAI's o3 AI model to discover a previously unknown vulnerability in the Linux kernel's SMB implementation, demonstrating AI's potential in identifying complex software flaws.

AI Model Uncovers Critical Linux Kernel Vulnerability

In a groundbreaking development, OpenAI's o3 artificial intelligence model has assisted a cybersecurity researcher in uncovering a zero-day vulnerability in the Linux kernel. This discovery marks a significant milestone in the application of AI to identify complex software flaws, potentially revolutionizing the field of cybersecurity 1.

Source: Beebom

Source: Beebom

The Discovery Process

Researcher Sean Heelan was initially testing the AI's capability against a known bug (CVE-2025-37778) in the Kerberos authentication system. Encouraged by o3's performance, Heelan decided to challenge the AI further by feeding it the entire file of the session setup command handler, containing approximately 12,000 lines of code 1.

During this process, o3 not only identified the known bug but also spotted an entirely new vulnerability that had previously gone unnoticed. This zero-day flaw, now tracked as CVE-2025-37899, was found in the Linux kernel's Server Message Block (SMB) implementation, specifically affecting the SMB 'logoff' command handler 2.

Nature of the Vulnerability

The newly discovered bug falls into the "use-after-free" category, a type of vulnerability where the system attempts to access memory that has been freed or deleted. In this case, the issue occurs when a user is logging out or ending a session, potentially leading to system crashes or allowing attackers to execute code with elevated privileges 1.

AI's Performance and Implications

While o3's performance in identifying the known Kerberos vulnerability varied across multiple runs, its ability to uncover a novel bug in a complex codebase is particularly noteworthy. Heelan observed that o3 demonstrated a human-like approach to bug hunting, contrasting with the rigid functionality of traditional security tools 1.

Source: NDTV Gadgets 360

Source: NDTV Gadgets 360

Resolution and Future Prospects

Following the discovery, a patch for the vulnerability has been swiftly developed and merged into the official Linux kernel repository on GitHub. This rapid response underscores the potential of AI-assisted vulnerability detection in enhancing software security 2.

Heelan suggests that while o3 is not infallible and has a high signal-to-noise ratio, recent advancements in AI reasoning models have significantly improved their ability to understand and analyze large codebases. For projects under 10,000 lines of code, models like o3 could prove invaluable in problem-solving and vulnerability research 2.

Comparative AI Model Performance

In his evaluation, Heelan also tested other AI models such as Claude 3.7 Sonnet and Claude 3.5 Sonnet. The results showed varying degrees of success in identifying the known Kerberos vulnerability, with o3 outperforming its counterparts 2.

This breakthrough demonstrates the growing potential of AI in cybersecurity, particularly in identifying complex vulnerabilities that might elude traditional methods. As AI models continue to evolve, they may become indispensable tools for researchers and developers in ensuring the security and integrity of critical software systems.

Explore today's top stories

Salesforce Acquires Informatica for $8 Billion to Boost AI and Data Management Capabilities

Salesforce has agreed to acquire Informatica, a cloud data management company, for $8 billion. The deal aims to enhance Salesforce's AI and data management capabilities, particularly in the realm of agentic AI.

The Register logoCNBC logoCRN logo

8 Sources

Business and Economy

2 hrs ago

Salesforce Acquires Informatica for $8 Billion to Boost AI

OnePlus Unveils AI-Powered 'Plus Mind' Feature and Replaces Alert Slider with 'Plus Key'

OnePlus introduces AI-driven 'Plus Mind' feature and replaces its iconic Alert Slider with a customizable 'Plus Key', signaling a major shift towards AI integration in its smartphones.

CNET logoengadget logoAndroid Authority logo

6 Sources

Technology

2 hrs ago

OnePlus Unveils AI-Powered 'Plus Mind' Feature and Replaces

The Great AI Debate: Imminent AGI vs. Normal Technology

A comprehensive look at the contrasting views on the future of AI, from those predicting imminent artificial general intelligence (AGI) to others arguing for a more measured, "normal technology" approach.

The New Yorker logoThe Seattle Times logo

2 Sources

Science and Research

2 hrs ago

The Great AI Debate: Imminent AGI vs. Normal Technology

AI's Impact on Knowledge Workers: From Job Displacement to Identity Crisis

As AI advances, knowledge workers face not just job losses but a profound identity crisis. This story explores the shift in the job market, personal experiences of displaced workers, and the broader implications for society.

VentureBeat logoQuartz logo

2 Sources

Business and Economy

2 hrs ago

AI's Impact on Knowledge Workers: From Job Displacement to

Cisco Research Predicts Agentic AI to Handle 68% of Customer Service Interactions by 2028

Cisco's latest research reveals a significant shift towards agentic AI in customer service, with predictions of it handling 68% of interactions by 2028. The study highlights the transformative potential of AI in improving customer experience and operational efficiency.

Cisco Blogs logoInvesting.com logo

2 Sources

Technology

2 hrs ago

Cisco Research Predicts Agentic AI to Handle 68% of
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Β© 2025 Triveous Technologies Private Limited
Twitter logo
Instagram logo
LinkedIn logo