Urgent.News

What's breaking now, across thousands of outlets.

AI

AI Finds So Many Linux Bugs, Canonical Changes to a Two-Week Stable Release Update Cycle

"Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster," writes Slashdot reader BrianFagioli AI has transformed bug discovery from "a manual, time-intensive process into a highly automated engine," notes Canonical's blog, leading to a "recent explosion in the volume of CVEs". Additionally, the upstream kernel community became its own CVE…

AI has revolutionized the process of discovering bugs in Linux, making it a highly automated and rapid engine. This transformation has led to an influx of Common Vulnerabilities and Exposures (CVEs) and a more significant role for the upstream kernel community in assigning CVE identifiers to thousands of bugs. Consequently, the number of CVEs has skyrocketed exponentially, creating a substantial backlog of alerts and necessitating a drastic increase in the speed of fixes to address the window of risk.

To tackle this growing volume of CVEs and the need for faster security fixes, Canonical is shifting to a unified, two-week release cycle. In the interim, while patches are being prepared, Canonical aims to provide safe workarounds, ensuring users remain secure. In scenarios where no safe workaround is available, Canonical will clearly inform users and recommend general hardening steps.

The ultimate objective is to ensure environments are in a defensible, safer state within 24 to 48 hours of public disclosure, well ahead of the patch's release. This strategy does not replace the patch but provides the essential time needed to fix the vulnerability properly, without compromising security. Nevertheless, there is an irony in this situation.

While AI is often seen as a tool to expedite software development, it is also accelerating the discovery of vulnerabilities, thereby compelling maintainers to expedite the other aspect as well. For Ubuntu users, this development is likely to be beneficial, as more bugs being discovered is better than vulnerabilities remaining undetected within the Linux kernel.

Written by urgent.news from Slashdot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at news.slashdot.org →

More in AI

The Self-Regulatory Moat

When three direct commercial competitors agree to establish an independent oversight body, the financial press usually frames it as responsible stewardship or an eleventh-hour attempt to stave off…

  • Google, OpenAI, and Anthropic form Standards Authority for Frontier AI (SAFA).
  • SAFA aims to standardize benchmarks, pre-deployment reviews, and incident disclosure.

More from Saturday 26 September →