{
  "id": 9587715,
  "title": "CVE flood pushes Ubuntu onto weekly kernel release cycle",
  "url": "https://urgent.news/2026/09/24/cve-flood-pushes-ubuntu-onto-weekly-kernel-release-cycle",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T16:33:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/os-platforms/2026/09/24/cve-flood-pushes-ubuntu-onto-weekly-kernel-release-cycle/5298912"
  },
  "original_language": "en",
  "account": "Canonical is accelerating Ubuntu kernel releases to one per week due to an overwhelming influx of CVEs, which AI-assisted bug hunting has contributed to. The company is transforming its kernel release process by overhauling the current four-week regular and two-week security cycles into overlapping two-week cycles, resulting in a weekly kernel release. This change is necessary to keep up with the surge in reported vulnerabilities, with AI playing a significant role in this trend. Large language models and specialized AI agents have revolutionized bug discovery, transforming it from a manual, time-consuming process into an automated engine. While AI is not entirely responsible for the CVE surge, Linux vendors now face an abundance of vulnerabilities to address. Canonical believes that faster releases are crucial to minimize the time between vulnerabilities being public and patched kernels reaching users. The new system consists of two weeks of integrating patches, preparing kernel packages, and conducting basic checks, followed by a week for hardware certification, distro integration, and regression testing. Upon completion, the kernel is released, enabling Canonical to publish release candidates within the first week and fully release the kernel the following week. For those who prefer a faster approach, organizations can utilize release candidates from the -proposed pocket after the first week and perform their own acceptance tests. Canonical provides safer workarounds and recommends hardening measures within 24 to 48 hours of public disclosure, aiming to leave customers less exposed between disclosure and patch availability. This results in a more extensive kernel release schedule, but it may be necessary as AI continues to expedite bug discovery, making patching more challenging.",
  "summary": "AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "CVE flood pushes Ubuntu onto weekly kernel release cycle",
        "url": "https://urgent.news/2026/09/24/cve-flood-pushes-ubuntu-onto-weekly-kernel-release-cycle-9590621",
        "published": "2026-09-24T16:33:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}