The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · Canonical · Ubuntu

Canonical moves Ubuntu to weekly kernels, cites AI bug discovery

The company says language models and specialised agents have turned bug hunting into an automated engine, and that CVE volume has grown past its old release cycle.

Canonical is replacing Ubuntu's kernel release cadence with overlapping two-week cycles that put out a kernel every week. The company says the change answers the number of vulnerabilities now being found. It set out the new strategy in a post on 23 September.

Canonical puts part of the growth down to automation. "Large language models (LLMs) and specialized AI agents have transformed bug discovery from a manual, time-intensive process into a highly automated engine," it wrote. The volume of CVEs "has skyrocketed exponentially", it said. The company gave no figure for how many kernel CVEs it now handles.

The second cause it names is procedural. The upstream Linux kernel community became a CVE Numbering Authority in 2024. It began issuing identifiers for thousands of bugs that had gone untracked, on the view that almost any kernel flaw on a running system may have security consequences.

Ubuntu used to ship a full kernel update every four weeks, with a security update two weeks later. The replacement runs a two-week cycle that starts a week apart. Week one is integration, builds and smoke tests, ending with release candidates in the -proposed pocket. Week two is certification and regression testing.

Teams that cannot wait can test the -proposed builds themselves and skip certification. Those builds refresh weekly. Canonical said it aims to get environments "into a defensible, safer state within 24 to 48 hours of public disclosure", with workarounds where a patch is not ready. The Register covered the change on Thursday.

Sources 2 sources

  1. Source Canonical
  2. Source The Register