ESPNRice bests Boone's belief by slugging homers 40, 41ESPN DeportesPortugal y CR7 debutan en la Nations LeagueBollywood HungamaSajid Nadiadwala’s Nadiadwala Grandson seals 11-month Andheri office space deal; pays Rs. 55 lakhs upfrontDaily MaverickLedgers of femicide: Why SA men think they’re the exceptionDigital SpyEastEnders confirms big Ash Panesar twist - here's what she's hidingAnime News NetworkCrunchyroll Screens Dive in Wonderland Film on November 16 in U.S. as Part of Anime Nights ProgramDeadlineApple TV Comedy ‘Protective Custody’ Rounds Out Cast With Five More AdditionsBillboardHere Are the Performers & Presenters for the 2026 VMAsPinkvillaAvengers Endgame Encore India Final Advance Booking: Marvel film sells 85,000 tickets in National Chains, eyes good startSportstarPortugal vs Wales LIVE SCORE - Cristiano Ronaldo almost scores in UEFA Nations League; POR vs WAL updatesWirtualna PolskaDwulatek wypił chemię budowlaną. Interweniował LPRCollider11 Years Later, This Forgotten 8-Part Fantasy Feels Like It Was Made To Be Binged
The Daily Newsstand · Free, Always
Thursday, September 24, 2026

CVE flood pushes Ubuntu onto weekly kernel release cycle

Translate

AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

Canonical is speeding up Ubuntu kernel releases to one a week as AI-assisted bug hunting helps bury defenders under an ever-growing pile of CVEs.

The Ubuntu maker is overhauling how it ships kernel Stable Release Updates (SRUs), replacing its current four-week regular and two-week security cycles with overlapping two-week cycles that will push a kernel release every week.

Canonical says the change is needed because the number of reported vulnerabilities has exploded, with AI deserving some of the credit – or blame, depending on which side of the patch queue you're sitting.

REG AD

"Large language models (LLMs) and specialized AI agents have transformed bug discovery from a manual, time-intensive process into a highly automated engine," Canonical said on Wednesday.

REG AD

AI isn't solely responsible for the CVE avalanche. The upstream Linux kernel community became a CVE Numbering Authority in 2024 and began assigning identifiers to thousands of bugs on the basis that almost any kernel flaw affecting a running system could have security implications.

Put the two together, and Linux vendors have far more CVEs to deal with. Canonical says the resulting backlog requires faster releases to shrink the window between vulnerabilities becoming public and patched kernels reaching users.

Under the new system, each SRU cycle lasts two weeks, but a new one starts every week. The first week is spent integrating patches, preparing and building kernel packages, and carrying out basic checks to make sure nothing catches fire. By the end of that stage, release candidates are published to Ubuntu's -proposed pocket.

Week two is reserved for the heavier stuff, including hardware certification, distro integration, and regression testing. Once that's done, the kernel is released. Because the next cycle starts while that testing is under way, Canonical can publish another kernel the following week.

For admins who consider even that too leisurely, there's a faster route.

Organizations particularly sensitive to patching delays can take release candidates from the -proposed pocket after the first week and run their own acceptance tests. Canonical makes the trade-off clear: those users get access to fixes sooner, but before the company has finished its extensive certification testing.

That can make kernel CVE fixes available within a week, provided customers are willing to perform some of the testing themselves.

Canonical also wants to leave customers less exposed between disclosure and patch availability. It aims to provide safe workarounds where possible, or recommend general hardening measures where none exist, putting systems into what it calls a "defensible, safer state" within 24 to 48 hours of public disclosure.

REG AD

Those measures are not intended to replace patching, merely to give admins something better than crossing their fingers while a fix makes its way through the release process.

The end result is a considerably busier kernel release schedule, although perhaps that's inevitable when machines are increasingly being enlisted to find bugs faster than humans can patch them.

AI was supposed to make everyone's jobs easier. Ubuntu's kernel team may want a word. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.