CVE-2025-37899General(linux / linux_kernel)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the session being free'd. The handler for that connection could be in the smb2_sess_setup function which makes use of sess->user.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-01-28); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-01-28: 1Mentions · 2026-02-06: 1Mentions · 2026-04-09: 1Mentions · 2026-04-22: 1Mentions · 2026-05-26: 1Mentions · 2026-07-29: 1PoC Mentioned / Linked · 2026-05-26: 1Technical Details · 2026-05-26: 1Technical Details · 2026-07-29: 101-2802-0604-0904-2205-2607-29
Signal classification2 categories
General
466.7%
Disclosure
233.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-281
General1
2026-02-061
Disclosure1
2026-04-091
General1
2026-04-221
General1
2026-05-261
General1
2026-07-291
Disclosure1
Full discourse6 posts
  • Alex Matrosov@matrosov
    General

    Plenty. A few Linux-kernel examples: CVE-2024-53141 - netfilter ipset one-bit OOB write that Mythos programmed into a PTE flipper CVE-2026-31402 - 23-year-old remote heap overflow in NFSv4 LOCK CVE-2025-37899 - ksmbd concurrent-thread UAF, found by @seanhn The Mythos red-team blog has a bunch more (FreeBSD NFS RPCSEC_GSS, AF_UNIX MSG_OOB cross-cache, Firefox JIT spray) if you want to go deeper.

    Post summary

    The note lists several Linux‑kernel CVEs with brief technical descriptors but offers no exploit code, patches, or evidence of active use.

    110101536
    20.1K followersView on X
  • zkSecurity@zksecurityXYZ
    Disclosure

    @seanhn showed this clearly: using o3 on Linux kernel SMB code, the model found the vulnerability in 8 out of 100 runs. In many runs it concluded there was no bug. The punchline: if you keep running it, you stop needing luck. https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/

    Post summary

    The tweet references a blog post where CVE‑2025‑37899 was discovered using a model, but it offers no PoC, exploit, patch, or active‑exploitation evidence, merely noting the discovery effort.

    10041546
    6.0K followersView on X
  • AI Risk Explorer (AIRE)@AIRiskExplorer
    General

    This is not new. In 2025, the company found three vulnerabilities in OpenSSL: https://aisle.com/blog/aisle-discovers-three-of-the-four-openssl-vulnerabilities-of-2025 Other researchers like @seanhn have also reported discovering zero-days using o3. https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/

    Post summary

    The post notes the discovery of several OpenSSL issues and a Linux kernel zero‑day but offers no PoC, exploit details, active exploitation evidence, or patch information.

    10020118
    174 followersView on X
  • Kimberly K. Maher@Peacemakerproje
    Disclosure

    C educators — May 2026 updates + a note on AI: • glibc CVE-2025-4802 (LD_LIBRARY_PATH in setuid binaries) • Linux ksmbd use-after-free (CVE-2025-37899), found with AI help • GCC 15 in Fedora 42 with C23 defaults • Clang/LLVM nearing full C23 support • @GitHub Copilot Coding Agent launched • @SQLite 3.50.0 (25th anniversary) AI is simply a tool. It is not here to replace you. You still know the students, notice when they’re stuck, and decide what help they need next. AI just makes everyday tasks easier so you have more time for real teaching. It can draft practice examples, suggest clearer explanations, clean up rough student code for comparison, or generate quick checks. Keep it plain and useful. Stay in charge — always check what it produces. Used this way, AI is a helpful assistant, not a replacement. You already do excellent work. Let’s explore AI carefully and keep the focus on the students. Thoughts? #CProgramming #CLang #C23 #AIinEducation #CodingEducation #EdTech

    Post summary

    The tweet announces updates on two CVEs, giving brief technical descriptions but no exploitation or patch details. It serves as a disclosure of the vulnerabilities’ existence and nature.

    0101058
    2.3K followersView on X
  • V-Aids galore in 2026 🏛️@PeylsX
    General

    @Rothmus and these days 15 and 25yr old vulnerabilities are found in #Linux in this "open source" software that everyone can "check" (SMB CVE-2025-37899) and Linus is a self proclaimed communist good luck with that Clown Show 🤣🤣🤡

    Post summary

    The tweet references a Linux SMB vulnerability (CVE‑2025‑37899) in a dismissive tone but provides no technical details, exploit code, or patch information.

    000101.0K
    120 followersView on X
  • Gerardo Eliasib@GerhSec
    General

    El salto en 12 meses: Mayo 2025 — CVE-2025-37899 Un investigador (Sean Heelan) usando o3 de OpenAI desde su suscripción personal. Humano al volante, IA como copiloto. Abril 2026 — CVE-2026-4747 Mythos, de Anthropic. Totalmente autónomo. Sin humano en el loop. De copiloto a piloto en un año.

    Post summary

    The tweet lists two CVEs with a brief timeline but offers no exploit, patch, or technical details.

    00000334
    84 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.15--
OSlinuxlinux_kernel6.15--
OSlinuxlinux_kernel6.15--
OSlinuxlinux_kernel6.15--

Explore more