OpenSSF A.I CyberSecurity Scoring
OpenSSF
Company Information
Website:https://openssf.org/
Employees number:27
Number of followers:12,746
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:openssf.org
OpenSSF Risk Score (AI oriented)
Between 700 and 749
OpenSSFIT Services and IT Consulting
Updated:
04/04/2026
04/04/2026
749/1000
Moderate
Ba
OpenSSF Global Score (TPRM)
xxxx
OpenSSFIT Services and IT Consulting
Score locked

OpenSSFModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
749
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
AUGUST 2025
748
JULY 2025
748
MAY 2025
749
Vulnerability
23 May 2025 • OpenSSF
Linux Foundation (Kernel Development Community)
Zero-Day Vulnerability in Linux Kernel SMB Implementation (CVE-2025-37899)
748
CRITICAL-1
OPE0925109112625
A zero-day use-after-free vulnerability (CVE-2025-37899) was discovered in the Linux kernel’s SMB (Server Message Block) implementation, specifically within the `ksmbd` module’s logoff command handler. The flaw arises due to improper synchronization between concurrent SMB session threads, where one thread frees the `sess->user` object while another continues accessing it, leading to memory corruption, system crashes, or potential privilege escalation.The vulnerability was uncovered using OpenAI’s o3 AI model, which analyzed the kernel code and identified unsafe memory access scenarios under concurrent execution. While no active exploitation has been reported, the flaw poses a critical risk to systems relying on SMB3 protocol implementations, including enterprise servers, NAS devices, and embedded Linux systems. A successful exploit could allow attackers to execute arbitrary code in kernel mode, compromising system integrity, confidentiality, and availability.The discovery also highlighted the effectiveness and limitations of AI-driven vulnerability research, with o3 demonstrating superior detection capabilities compared to other models but still producing a high false-positive rate. Patches are expected to be released in upcoming kernel updates, but unpatched systems remain exposed to remote code execution (RCE) attacks via malicious SMB connections.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for OpenSSF ??
What was OpenSSF's A.I Rankiteo Cyber Score in May 2026 ??
What was OpenSSF's A.I Rankiteo Cyber Score in April 2026 ??
What was OpenSSF's A.I Rankiteo Cyber Score in March 2026 ??
What was OpenSSF's A.I Rankiteo Cyber Score in February 2026 ??
What was OpenSSF's A.I Rankiteo Cyber Score in January 2026 ??
What was OpenSSF's A.I Rankiteo Cyber Score in December 2025 ??
What was OpenSSF's A.I Rankiteo Cyber Score in November 2025 ??
What was OpenSSF's A.I Rankiteo Cyber Score in October 2025 ??
What was OpenSSF's A.I Rankiteo Cyber Score in September 2025 ??
What was OpenSSF's A.I Rankiteo Cyber Score in August 2025 ??
What was OpenSSF's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on OpenSSF's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with OpenSSF ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view OpenSSF's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?