Back
CVE flood pushes Ubuntu onto weekly kernel release cycle
SiTech AI Team3 წთ. საკითხავი

CVE flood pushes Ubuntu onto weekly kernel release cycle

Canonical is replacing Ubuntu's four-week regular and two-week security kernel cycles with overlapping two-week cycles that publish a kernel release every week, as AI-assisted bug hunting piles up CVEs.

Canonical is putting Ubuntu on a weekly kernel release rhythm. The company is overhauling how it ships kernel Stable Release Updates (SRUs), replacing its current four-week regular and two-week security cycles with overlapping two-week cycles that will push out a kernel release every week.

Why the schedule is changing

Canonical says the change is needed because the number of reported vulnerabilities has exploded, and AI deserves some of the credit — or blame, depending on which side of the patch queue you sit on. "Large language models (LLMs) and specialized AI agents have transformed bug discovery from a manual, time-intensive process into a highly automated engine," the company said.

AI is not the only factor. The upstream Linux kernel community became a CVE Numbering Authority in 2024 and began assigning identifiers to thousands of bugs on the basis that almost any kernel flaw affecting a running system could have security implications. Put the two together and Linux vendors have far more CVEs to handle; Canonical says the resulting backlog requires faster releases to shrink the window between a vulnerability becoming public and a patched kernel reaching users.

How the new cycle works

Each SRU cycle lasts two weeks, but a new one starts every week. The first week is spent integrating patches, preparing and building kernel packages, and carrying out basic checks; by the end of that stage, release candidates are published to Ubuntu's -proposed pocket. Week two is reserved for heavier work — hardware certification, distro integration and regression testing — after which the kernel is released. Because the next cycle starts while that testing is under way, Canonical can publish another kernel the following week.

For organizations that consider even that too slow, there is a faster route: after the first week they can take release candidates from the -proposed pocket and run their own acceptance tests. Canonical makes the trade-off clear — those users get fixes sooner, but before the company has finished its extensive certification testing. That can make kernel CVE fixes available within a week, provided customers are willing to perform some of the testing themselves.

Covering the gap before patches arrive

Canonical also wants customers to be less exposed between disclosure and patch availability. Where possible it aims to provide safe workarounds, or to recommend general hardening measures where none exist, putting systems into what it calls a "defensible, safer state" within 24 to 48 hours of public disclosure. Those measures are not intended to replace patching; they are meant to give admins something better than crossing their fingers while a fix works its way through the release process.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.