SECOND MEASUREMENT SM-008

A federal directive says CISA rates every CVE. Since March, it has rated almost no Linux kernel bugs

Markovian ProtocolMeasured 2026-10-02Status: sent to CISA (issue 262) and the kernel CVE team 2026-10-02, responses pendingDOI: 10.5281/zenodo.23122997

In June, CISA told every federal agency to set its patching deadlines from three answers CISA says it publishes “for every CVE ID”. We checked. Every one of the 1,731 actively exploited CVEs has them, and so does every other CVE in our sample. Linux kernel CVEs don't: 1 of the 158 we sampled since March carries them. That's about 5,000 kernel CVEs since the directive with nothing to set a deadline from, in the middle of a public fight between CISA and the kernel's own security team.

The short version

Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisation measured. How we work.

Details

CISA’s Vulnrichment program adds a container to CVE records with three yes/no-style answers, a scheme called SSVC: is it being exploited, can an attacker automate it, and does it give partial or total control. Binding Operational Directive 26-04 makes those answers, plus whether the system is exposed to the internet, the inputs that set how fast federal agencies must patch. We read the CISA container on every CVE in the known-exploited catalog, a random 400 published since the directive, and 15 random kernel CVEs per month back to March 2025.

What they said, what we found

CISA saidWe found
“CISA publishes answers to KEV Status, Exploit Automation, and Technical Impact for every CVE ID through services such as the Vulnrichment Program.” (BOD 26-04, 10 June 2026)1True for 1,731 of 1,731 known-exploited CVEs and 335 of 335 recent CVEs from other sources. True for 0 of 53 recent Linux kernel CVEs.
“The urgency of vulnerability remediation … is determined based on” those answers and asset exposure.15,024 kernel CVEs were published between the directive and 30 September. From our sample, almost none have CISA’s answers to determine it from.

The fight

WhenWhat happened, on CISA’s own issue tracker2
30 Jan 2026The kernel’s CVE team asks CISA to stop adding severity scores to kernel CVEs, arguing that there is no single correct CVSS score for most kernel bugs.
29 MarGreg Kroah-Hartman sets a deadline: if CISA doesn’t answer by 31 March, the kernel team will publish its own scores, and “It might contain a bit higher number than you expect”.
March onwardOur sample: CISA’s answers stop appearing on new kernel CVEs.
10 JunBOD 26-04: CISA publishes the answers “for every CVE ID”.1
31 JulA CISA participant in the thread: “I believe Vulnrichment has paused all CVSS assessments for Linux kernel CVE Records pending the outcome of this discussion.”
1 AugSasha Levin, for the kernel team: “We weren’t told. We found out from your comment.”
TodayThe issue is open. Its last comment before ours is dated 3 August.

The pause CISA described was for CVSS scores. The three directive answers are a separate field, and the data shows they stopped too.

The count

SetCVEs checkedWith all three answers
Every CVE in the known-exploited catalog1,7311,731
Random sample from 9 June, all other sources335335
Random sample from 9 June, Linux kernel530

CVE records read from CVE Services on 2 October 2026; 12 rejected CVEs dropped from the sample.

Kernel CVEs month by month, 15 drawn at random from each:

MonthKernel CVEs publishedWith CISA’s answers
2025-0321411 of 15
2025-063890 of 15
2025-098476 of 15
2025-121,0952 of 15
2026-012493 of 15
2026-022221 of 15
2026-031800 of 15
2026-043820 of 15
2026-051,0340 of 15
2026-065140 of 15
2026-078381 of 15
2026-081,6500 of 15
2026-092,1170 of 15

Coverage was patchy through 2025 and fell to almost nothing from March 2026, the month of the deadline. Meanwhile the kernel publishes more of them: 2,117 in September, the most of any month we sampled.

The kernel CVEs CISA does rate are real. Two the kernel team mentioned in the thread, CVE-2026-53264 and CVE-2026-53359, were cited there for a CWE added in July; they are outside our sample.

How this ends

It ends when CISA’s answers reappear on kernel CVEs, which the weekly recheck samples (30 kernel, 30 other, each week), or when the directive is amended to say what it actually covers. Either is a public act; the page prints whichever comes.

The evidence

Every quote below was copied from the source and checked against a saved copy, fetched 2026-10-02T17:51:35Z. The copies and their SHA-256 hashes are published next to this page (SHA256SUMS).

Exhibit 1 · The directive, 10 June 2026

“CISA publishes answers to KEV Status, Exploit Automation, and Technical Impact for every CVE ID through services such as the Vulnrichment Program.”

cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk · saved copy cisa-bod-26-04.html

Exhibit 2 · A known-exploited CVE: the answers are there

CVE-2024-3400, CISA-ADP container:
"options": [ {"Exploitation": "active"}, {"Automatable": "yes"},
             {"Technical Impact": "total"} ]

cveawg.mitre.org/api/cve/CVE-2024-3400 · raw CVE-2024-3400.json

Exhibit 3 · A Linux kernel CVE: no CISA container at all

CVE-2026-64117, assigner "Linux", published 2026-07-19
"containers": { "cna": { … } }   (no adp array at all)

cveawg.mitre.org/api/cve/CVE-2026-64117 · raw CVE-2026-64117.json

Exhibit 4 · CISA, 31 July

“I believe Vulnrichment has paused all CVSS assessments for Linux kernel CVE Records pending the outcome of this discussion.”

cisagov/vulnrichment#262, comment by amanion-cisa · all comments saved: vulnrichment-262-comments.json

Exhibit 5 · The kernel team, 1 August

“We weren’t told. We found out from your comment.”

cisagov/vulnrichment#262, comment by sashalevin

Our questions to CISA

Sent to CISA on cisagov/vulnrichment issue 262 on 2 October 2026. Answers will be printed here as written.

  1. Does BOD 26-04’s “for every CVE ID” include Linux kernel CVEs?
  2. Is SSVC enrichment, not only CVSS, paused for kernel CNA records? Since when?
  3. How should agencies set BOD 26-04 deadlines for kernel CVEs that carry no CISA answers?
  4. Will CISA add SSVC answers to the kernel CVEs published since March 2026?
  5. How are the kernel CVEs that do get SSVC answers chosen?
  6. Was the kernel CVE team told about the pause before it was mentioned on issue 262?

Their reply, scored

Waiting for a reply. When it comes, each question gets marked answered, partly answered or not answered, and the reply goes here in full.

Disclosure timeline

2 OctPublished; sent to the kernel CVE team; posted on CISA’s issue tracker (#262).
2 OctSix numbered questions posted for CISA.
3 OctThe kernel CVE team replied, asking what the note was for. Nothing in it is theirs to act on; the actor here is CISA. Answered the same day.

Waiting on CISA since 2 Oct.

What we can’t be sure of

Run it yourself

Python 3 standard library. The NVD API without a key allows a request every few seconds, so the month table takes about ten minutes.

python3 cisa_ssvc.py kev      # every known-exploited CVE
python3 cisa_ssvc.py recent   # random 400 since 10 June, split by source
python3 cisa_ssvc.py months   # 15 kernel CVEs per month

Reproduced from the public repository on 3 October 2026 on a clean machine: exact (kernel 0 of 53, others 335 of 335, 1 of 105 by month, 5,024 kernel CVEs since the directive). The known-exploited pass takes about 15 minutes. Full table on the track record.

What you can do with this

References

  1. CISA. BOD 26-04: Prioritizing Security Updates Based on Risk. 10 June 2026. cisa.gov.
  2. cisagov/vulnrichment issue 262, “Request: Exclude kernel.org CVEs from CVSS/CWE enrichment”, opened 30 January 2026, 36 comments, open on 2 October 2026.
  3. CISA. Vulnrichment. github.com/cisagov/vulnrichment.
  4. CVE Services API, cveawg.mitre.org/api/cve/<id>; NVD CVE API 2.0, services.nvd.nist.gov/rest/json/cves/2.0.

Cite as

@misc{markovian-sm008,
  author = {{Markovian Protocol}},
  title  = {CISA's Vulnrichment answers and the Linux kernel, 2025-2026},
  number = {SM-008},
  doi    = {10.5281/zenodo.23122997},
  year   = {2026},
  month  = oct,
  url    = {https://markovianprotocol.com/measurements/sm-008.html}
}