SECOND MEASUREMENT SM-008
A federal directive says CISA rates every CVE. Since March, it has rated almost no Linux kernel bugs
In June, CISA told every federal agency to set its patching deadlines from three answers CISA says it publishes “for every CVE ID”. We checked. Every one of the 1,731 actively exploited CVEs has them, and so does every other CVE in our sample. Linux kernel CVEs don't: 1 of the 158 we sampled since March carries them. That's about 5,000 kernel CVEs since the directive with nothing to set a deadline from, in the middle of a public fight between CISA and the kernel's own security team.
- CISA’s BOD 26-04 (10 June 2026) sets federal patch deadlines from three answers CISA says it publishes “for every CVE ID”.
- All 1,731 of 1,731 known-exploited CVEs carry them, and so do 335 of 335 other recent CVEs we sampled.
- Linux kernel CVEs: 0 of 53 sampled since the directive, 1 of 158 since March.
- That is about 5,024 kernel CVEs since 10 June with nothing to set a deadline from.
- It coincides with an open dispute in which a CISA participant said kernel CVSS work was paused, and the kernel team said it hadn’t been told.
Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisation measured. How we work.
CISA’s Vulnrichment program adds a container to CVE records with three yes/no-style answers, a scheme called SSVC: is it being exploited, can an attacker automate it, and does it give partial or total control. Binding Operational Directive 26-04 makes those answers, plus whether the system is exposed to the internet, the inputs that set how fast federal agencies must patch. We read the CISA container on every CVE in the known-exploited catalog, a random 400 published since the directive, and 15 random kernel CVEs per month back to March 2025.
What they said, what we found
| CISA said | We found |
|---|---|
| “CISA publishes answers to KEV Status, Exploit Automation, and Technical Impact for every CVE ID through services such as the Vulnrichment Program.” (BOD 26-04, 10 June 2026)1 | True for 1,731 of 1,731 known-exploited CVEs and 335 of 335 recent CVEs from other sources. True for 0 of 53 recent Linux kernel CVEs. |
| “The urgency of vulnerability remediation … is determined based on” those answers and asset exposure.1 | 5,024 kernel CVEs were published between the directive and 30 September. From our sample, almost none have CISA’s answers to determine it from. |
The fight
| When | What happened, on CISA’s own issue tracker2 |
|---|---|
| 30 Jan 2026 | The kernel’s CVE team asks CISA to stop adding severity scores to kernel CVEs, arguing that there is no single correct CVSS score for most kernel bugs. |
| 29 Mar | Greg Kroah-Hartman sets a deadline: if CISA doesn’t answer by 31 March, the kernel team will publish its own scores, and “It might contain a bit higher number than you expect”. |
| March onward | Our sample: CISA’s answers stop appearing on new kernel CVEs. |
| 10 Jun | BOD 26-04: CISA publishes the answers “for every CVE ID”.1 |
| 31 Jul | A CISA participant in the thread: “I believe Vulnrichment has paused all CVSS assessments for Linux kernel CVE Records pending the outcome of this discussion.” |
| 1 Aug | Sasha Levin, for the kernel team: “We weren’t told. We found out from your comment.” |
| Today | The issue is open. Its last comment before ours is dated 3 August. |
The pause CISA described was for CVSS scores. The three directive answers are a separate field, and the data shows they stopped too.
The count
| Set | CVEs checked | With all three answers |
|---|---|---|
| Every CVE in the known-exploited catalog | 1,731 | 1,731 |
| Random sample from 9 June, all other sources | 335 | 335 |
| Random sample from 9 June, Linux kernel | 53 | 0 |
CVE records read from CVE Services on 2 October 2026; 12 rejected CVEs dropped from the sample.
Kernel CVEs month by month, 15 drawn at random from each:
| Month | Kernel CVEs published | With CISA’s answers |
|---|---|---|
| 2025-03 | 214 | 11 of 15 |
| 2025-06 | 389 | 0 of 15 |
| 2025-09 | 847 | 6 of 15 |
| 2025-12 | 1,095 | 2 of 15 |
| 2026-01 | 249 | 3 of 15 |
| 2026-02 | 222 | 1 of 15 |
| 2026-03 | 180 | 0 of 15 |
| 2026-04 | 382 | 0 of 15 |
| 2026-05 | 1,034 | 0 of 15 |
| 2026-06 | 514 | 0 of 15 |
| 2026-07 | 838 | 1 of 15 |
| 2026-08 | 1,650 | 0 of 15 |
| 2026-09 | 2,117 | 0 of 15 |
Coverage was patchy through 2025 and fell to almost nothing from March 2026, the month of the deadline. Meanwhile the kernel publishes more of them: 2,117 in September, the most of any month we sampled.
The kernel CVEs CISA does rate are real. Two the kernel team mentioned in the thread, CVE-2026-53264 and CVE-2026-53359, were cited there for a CWE added in July; they are outside our sample.
How this ends
It ends when CISA’s answers reappear on kernel CVEs, which the weekly recheck samples (30 kernel, 30 other, each week), or when the directive is amended to say what it actually covers. Either is a public act; the page prints whichever comes.
The evidence
Every quote below was copied from the source and checked against a saved copy, fetched 2026-10-02T17:51:35Z. The copies and their SHA-256 hashes are published next to this page (SHA256SUMS).
Exhibit 1 · The directive, 10 June 2026
“CISA publishes answers to KEV Status, Exploit Automation, and Technical Impact for every CVE ID through services such as the Vulnrichment Program.”
cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk · saved copy cisa-bod-26-04.html
Exhibit 2 · A known-exploited CVE: the answers are there
CVE-2024-3400, CISA-ADP container:
"options": [ {"Exploitation": "active"}, {"Automatable": "yes"},
{"Technical Impact": "total"} ]cveawg.mitre.org/api/cve/CVE-2024-3400 · raw CVE-2024-3400.json
Exhibit 3 · A Linux kernel CVE: no CISA container at all
CVE-2026-64117, assigner "Linux", published 2026-07-19
"containers": { "cna": { … } } (no adp array at all)cveawg.mitre.org/api/cve/CVE-2026-64117 · raw CVE-2026-64117.json
Exhibit 4 · CISA, 31 July
“I believe Vulnrichment has paused all CVSS assessments for Linux kernel CVE Records pending the outcome of this discussion.”
cisagov/vulnrichment#262, comment by amanion-cisa · all comments saved: vulnrichment-262-comments.json
Exhibit 5 · The kernel team, 1 August
“We weren’t told. We found out from your comment.”
Our questions to CISA
Sent to CISA on cisagov/vulnrichment issue 262 on 2 October 2026. Answers will be printed here as written.
- Does BOD 26-04’s “for every CVE ID” include Linux kernel CVEs?
- Is SSVC enrichment, not only CVSS, paused for kernel CNA records? Since when?
- How should agencies set BOD 26-04 deadlines for kernel CVEs that carry no CISA answers?
- Will CISA add SSVC answers to the kernel CVEs published since March 2026?
- How are the kernel CVEs that do get SSVC answers chosen?
- Was the kernel CVE team told about the pause before it was mentioned on issue 262?
Their reply, scored
Disclosure timeline
| 2 Oct | Published; sent to the kernel CVE team; posted on CISA’s issue tracker (#262). |
| 2 Oct | Six numbered questions posted for CISA. |
| 3 Oct | The kernel CVE team replied, asking what the note was for. Nothing in it is theirs to act on; the actor here is CISA. Answered the same day. |
Waiting on CISA since 2 Oct.
What we can’t be sure of
- Kernel coverage comes from samples: 53 since the directive and 15 per month. The pattern is consistent, but the exact rate isn’t known. 1 of 158 since March puts it under about 4% with 95% confidence.
- CISA may answer for kernel CVEs some other way. The directive names Vulnrichment, and that is where we looked.
- We don’t know whether the gap is a decision, a backlog, or a side effect of the CVSS pause.
- Agencies can still patch kernel bugs. What’s missing is the input the directive tells them to schedule by.
Run it yourself
Python 3 standard library. The NVD API without a key allows a request every few seconds, so the month table takes about ten minutes.
python3 cisa_ssvc.py kev # every known-exploited CVE python3 cisa_ssvc.py recent # random 400 since 10 June, split by source python3 cisa_ssvc.py months # 15 kernel CVEs per month
Reproduced from the public repository on 3 October 2026 on a clean machine: exact (kernel 0 of 53, others 335 of 335, 1 of 105 by month, 5,024 kernel CVEs since the directive). The known-exploited pass takes about 15 minutes. Full table on the track record.
What you can do with this
- If you triage with CISA's SSVC answers, kernel CVEs since March carry none; score them from the kernel team's own data.
- If you run Linux, the volume is about 2,000 kernel CVEs a month; a tool that waits for enrichment waits forever.
References
- CISA. BOD 26-04: Prioritizing Security Updates Based on Risk. 10 June 2026. cisa.gov.
- cisagov/vulnrichment issue 262, “Request: Exclude kernel.org CVEs from CVSS/CWE enrichment”, opened 30 January 2026, 36 comments, open on 2 October 2026.
- CISA. Vulnrichment. github.com/cisagov/vulnrichment.
- CVE Services API,
cveawg.mitre.org/api/cve/<id>; NVD CVE API 2.0,services.nvd.nist.gov/rest/json/cves/2.0.
Cite as
@misc{markovian-sm008,
author = {{Markovian Protocol}},
title = {CISA's Vulnrichment answers and the Linux kernel, 2025-2026},
number = {SM-008},
doi = {10.5281/zenodo.23122997},
year = {2026},
month = oct,
url = {https://markovianprotocol.com/measurements/sm-008.html}
}