Ubuntu Kernels Move to Weekly Releases as the CVE Flood Grows

Ubuntu Kernels Move to Weekly Releases as the CVE Flood Grows

Canonical announced on September 23 that Ubuntu kernel updates are moving to a weekly release rhythm. The new process started with the cycle beginning September 28.

Old process vs new

Previously, Ubuntu kernels followed two overlapping schedules: a four-week stable release update (SRU) cycle for regular fixes, and a two-week cycle for security fixes.

Now there is a single two-week cycle, and a new one starts every week, so cycles overlap and a kernel ships every seven days:

WeekWhat happens
Week 1Patches integrated, packages built, initial smoke tests. Candidate kernels published to -proposed
Week 2Certification, integration, and regression testing, then release to users

The important detail is that testing is not compressed. Each kernel still gets two weeks; there are simply two in the pipeline at once.

Why

Canonical was direct about the cause: the volume of kernel CVEs. It named two drivers:

The fast track

If a fix matters to you before certification finishes, there is now a sanctioned route: candidate kernels sit in the -proposed pocket about a week ahead of release. Enabling -proposed affects every package, not just the kernel, so pin it narrowly or use it on test systems.

For vulnerabilities with no fix yet, Canonical says it will aim to publish mitigations or workarounds within 24 to 48 hours where feasible, and hardening advice where not.

What it means for you

More frequent kernel updates are only useful if you install and boot them. Our guide to checking whether your kernel is patched against a CVE covers how to confirm what you are running, and keeping Linux updated covers automating updates and scheduling reboots. Kernel live patching can cover some fixes between reboots.

Background reading

Explainers for the concepts behind this story.