Ubuntu Kernel Updates Shift to Weekly Releases for Faster CVE Fixes
Canonical is consolidating Ubuntu kernel update schedules, moving to a weekly release cadence to deliver critical CVE fixes more rapidly to users.

Canonical, the company behind Ubuntu, is implementing a significant change to its kernel update strategy, consolidating its previous four-week Stable Release Update (SRU) cycle and its two-week security fix schedule into a single, unified two-week release cycle. This strategic shift is designed to provide Ubuntu users with more frequent and streamlined access to critical security patches for kernel vulnerabilities.
The new schedule effectively results in weekly kernel releases. This is achieved by overlapping the SRU and security fix cycles, with each new cycle beginning one week after the previous one. This overlapping structure ensures that administrators have a consistent and predictable pathway to obtain essential CVE fixes, reducing the waiting period for critical patches.
For administrators who require kernel CVE fixes even faster than the standard cycle allows, Canonical is offering a new sanctioned method. Users can opt to pull release candidates from the -proposed pocket of the Ubuntu archive. These builds are made available within a week, ahead of Canonical's full certification testing. This provides a faster lane for critical fixes, but it requires users to accept a degree of risk, as these builds have not yet undergone the full suite of certification tests.
Canonical aims to publish workarounds for disclosed vulnerabilities within 24 to 48 hours of public disclosure, provided a safe workaround exists. In cases where no immediate workaround is available, the company will direct users to general hardening steps and best practices to mitigate potential risks. This proactive approach seeks to minimize the window of exposure for Ubuntu systems.
The driving force behind this change is the increasing volume of Common Vulnerabilities and Exposures (CVEs). The proliferation of AI and LLMs has automated much of the bug-hunting process, leading to a surge in disclosed vulnerabilities. Furthermore, the upstream Linux kernel community's decision to become its own CVE Numbering Authority has resulted in the assignment of identifiers to thousands of bugs, many of which could potentially be exploited.
Canonical emphasizes that while expedited releases are available through the -proposed pocket, full testing remains a priority for all official releases. The company acknowledges that "expedited releases aren’t possible while thoroughly testing every release candidate." Therefore, teams opting for the faster -proposed builds must be prepared to conduct their own acceptance testing and assume responsibility for any regressions that may be present in these uncertified builds.
This new weekly release schedule for Ubuntu kernel updates represents a significant adjustment for system administrators. They will need to plan for more frequent updates and carefully evaluate which systems can tolerate the potential risks associated with deploying uncertified builds from the -proposed pocket to achieve the fastest possible access to critical security patches.