Trending: On-device modelsSearch
iHeartGeek
iTECH

Canonical speeds up Ubuntu kernel fixes to a weekly cadence

Canonical is replacing its staggered four-week and two-week kernel updates with one rolling cycle that ships every week, because AI has turned CVE hunting into an industry.

Canonical's announcement card headlined 'Accelerating delivery of CVE fixes with a new Kernel release strategy', above the line 'Discover how faster patch releases will help defend your systems in the age of AI-driven CVEs'

Canonical is halving the time Ubuntu users wait for kernel security fixes. In a post published on 23 September, the company said it is dropping its separate four-week regular and two-week security kernel Stable Release Update cycles in favour of a single two-week cycle, and because those cycles overlap, kernel releases will now arrive every week.

How the weekly cycle works

The fortnight is split by job. Week one is preparation: Canonical picks the patches that land in each kernel, integrates them, takes a snapshot of the tree at a cutoff date and runs initial sanity checks, with builds published in the -proposed pocket by the end of that stage. Week two is the long part, covering certification, distribution integration and regression testing through the Ubuntu Certified hardware programme. The cycles cascade, so one week's testing runs alongside the next week's preparation.

Why the timetable moved

Volume, not fashion. Canonical attributes the CVE flood to artificial intelligence: large language models and specialised agents have turned bug discovery from slow manual work into an automated engine, while the upstream kernel community became its own CVE Numbering Authority and started assigning identifiers to thousands of bugs on the argument that almost anything able to affect a running system counts as a vulnerability. A monthly rhythm cannot keep up with that queue.

What changes for anyone running Ubuntu

Canonical insists the testing is not being traded away, and that expedited releases are simply impossible while every release candidate is certified. Teams that cannot wait for certification can run their own acceptance tests against the weekly candidates in the proposed pocket, which is where those builds sit before certification begins. While a patch is being prepared, Canonical says it will publish safe workarounds where they exist, so a fleet can be made defensible within 24 to 48 hours of a public disclosure, and that where no workaround exists it will say so plainly rather than imply otherwise.

Our opinion

Patch cadence is the least glamorous dial in security and one of the few that changes outcomes on its own. Canonical has been honest about the arithmetic: the machines hunting bugs now outpace the humans who fix, test and ship them, and a four-week comfort blanket was always going to lose that race. The bargain worth watching is the one buried in the middle of the post. Users who cannot wait for certification are pointed at the proposed pocket, which is the right call for a bank and a poor one for anyone who simply wants a quiet server. Weekly kernels also mean weekly reboots and a much smaller window between an upstream regression and your estate. Canonical has bought speed; the regression numbers over the next two quarters will show what it cost.