CVE flood pushes Ubuntu onto weekly kernel release cycle
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
Canonical, the maker of Ubuntu, is accelerating its kernel releases to once per week due to an overwhelming number of newly discovered vulnerabilities, many attributed to advancements in artificial intelligence. The company has revamped its kernel release process, shifting from traditional four-week regular and two-week security cycles to overlapping two-week cycles that will issue a kernel update every week.
This change is driven by the exponential growth in reported vulnerabilities, which AI has both aided and exacerbated. AI has transformed vulnerability discovery from a manual, time-consuming task to an automated process, leading to a surge in Common Vulnerabilities and Exposures (CVEs). The upstream Linux kernel community gained CVE Numbering Authority status in 2024 and began assigning identifiers to thousands of bugs, assuming all kernel flaws pose potential security risks.
With a larger pool of CVEs, Canonical and other Linux vendors must expedite releases to address vulnerabilities promptly and reduce the window between public disclosure and patched kernels. Under the new system, each SRU cycle lasts two weeks, but a new cycle initiates every week. The first week focuses on integrating patches, building kernel packages, and performing basic checks, with release candidates published to Ubuntu's -proposed pocket.
The second week is dedicated to hardware certification, distro integration, and regression testing before the final kernel release. For those who desire quicker updates, organizations can directly access release candidates from the -proposed pocket after the first week and conduct their own acceptance tests. Although this route offers faster access to fixes, Canonical warns that it skips extensive certification testing.
To mitigate risks between vulnerability disclosure and patch availability, Canonical aims to provide safe workarounds or general hardening measures within 24 to 48 hours of public disclosure. This proactive approach aims to leave systems in a "defensible, safer state" until official patches are released, despite the increased kernel release pace necessitated by AI-driven vulnerability discovery.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- CVE flood pushes Ubuntu onto weekly kernel release cycle theregister.com