Ubuntu Kernels Move to Weekly Releases as the CVE Flood Grows
Canonical announced on September 23 that Ubuntu kernel updates are moving to a weekly release rhythm. The new process started with the cycle beginning September 28.
Old process vs new
Previously, Ubuntu kernels followed two overlapping schedules: a four-week stable release update (SRU) cycle for regular fixes, and a two-week cycle for security fixes.
Now there is a single two-week cycle, and a new one starts every week, so cycles overlap and a kernel ships every seven days:
| Week | What happens |
|---|---|
| Week 1 | Patches integrated, packages built, initial smoke tests. Candidate kernels published to -proposed |
| Week 2 | Certification, integration, and regression testing, then release to users |
The important detail is that testing is not compressed. Each kernel still gets two weeks; there are simply two in the pipeline at once.
Why
Canonical was direct about the cause: the volume of kernel CVEs. It named two drivers:
- Automated vulnerability discovery, including AI-assisted tools, is finding more bugs than before. That matches what has been visible all Linux 7.3 cycle, and in September’s public root exploits for four networking bugs, found with AI-assisted analysis
- The Linux kernel becoming its own CVE Numbering Authority in 2024 means far more fixes receive CVE IDs
The fast track
If a fix matters to you before certification finishes, there is now a sanctioned route: candidate kernels sit in the -proposed pocket about a week ahead of release. Enabling -proposed affects every package, not just the kernel, so pin it narrowly or use it on test systems.
For vulnerabilities with no fix yet, Canonical says it will aim to publish mitigations or workarounds within 24 to 48 hours where feasible, and hardening advice where not.
What it means for you
More frequent kernel updates are only useful if you install and boot them. Our guide to checking whether your kernel is patched against a CVE covers how to confirm what you are running, and keeping Linux updated covers automating updates and scheduling reboots. Kernel live patching can cover some fixes between reboots.