Keeping pace with the machines
Ubuntu speeds up kernel security updates because of AI
by by Joey Sneddon · omg! ubuntu · JoinUbuntu kernel updates are about to become more frequent, as Canonical attempts to keep up with an ‘explosion’ in security vulnerabilities being discovered with the help of AI.
The company has announced it’s adopting a ‘unified’ two-week stable release update (SRU) cycle for kernel updates, which will speed up patching, testing and releasing fixes to users.
Ubuntu kernel engineers previously followed a 4/2 update schedule, releasing a full kernel update every 4 weeks and an urgent update (if needed) 2 weeks later. That was introduced in 2023 after criticism in how it long it took to roll out patches for Zenbleed.
Now, things are getting faster again.
Updates will track along a new ‘two-week’ repeating cadence which, in effect, will see Ubuntu kernel fixes rolling out on a weekly basis, as this graphic from the company shows:
The reason for the change is the obvious one. Canonical describes the “explosion” in bugs and CVEs, driven largely by researchers using AI models and agents to uncovering issues, as necessitating a new approach.
Which makes sense. Flaws are being found faster than ever, so patches have to follow suit. If not, users – and companies – who rely on Ubuntu are potentially left vulnerable to attack or exploit.
Canonical’s kernel engineers will now follow a two-week schedule. Week one sees it prep patches and builds and make them available for testing, while week two sees testing and certification completed and the stable updates roll out to systems.
Those who think they need expedited coverage, and don’t wish to to wait until Canonical has finished testing, will be able to enable the -proposed update pocket to update sooner – itself not without risk.
And for those who may feel they need immediate protection from a vulnerability, Canonical says it aims to provide or document workarounds within 24-48 hours of a vulnerability being identified to “get environments into a defensible, safer state[…] before a patch ships”.
If no safe workaround is known, it says is will point users toward general hardening steps instead.