<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v" -->

---
title: Canonical speeds up Ubuntu kernel updates to keep pace...
description: Canonical is switching Ubuntu kernel updates to a unified two-week stable release update cycle starting September 28, 2026, replacing the prior split schedule...
canonical: https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Canonical speeds up Ubuntu kernel updates to keep pace with AI-driven CVE flood | daily.dev
og:description: Canonical is switching Ubuntu kernel updates to a unified two-week stable release update cycle starting September 28, 2026, replacing the prior split schedule...
og:url: https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v
og:image: https://api.daily.dev/og/posts/bA99QjM4V.png
og:image:alt: Canonical speeds up Ubuntu kernel updates to keep pace with AI-driven CVE flood
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Canonical speeds up Ubuntu kernel updates to keep pace with AI-driven CVE flood

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Canonical is switching Ubuntu kernel updates to a unified two-week stable release update cycle starting September 28, 2026, replacing the prior split schedule of four-week feature updates and two-week security patches. The change responds to a surge in CVE reports driven by AI-assisted vulnerability discovery and the upstream Linux kernel community becoming its own CVE Numbering Authority. Canonical will also aim to publish workarounds or hardening guidance within 24-48 hours of public disclosure, ahead of full patches, and users can opt into the untested `-proposed` pocket for earlier fixes.

## Content

Canonical is consolidating Ubuntu's kernel update schedule into a single two-week stable release update (SRU) cycle, effective 28 September 2026. The change replaces the previous split schedule — a four-week cycle for feature updates and a separate two-week cycle for security patches — that Canonical adopted in 2023 after criticism over how slowly it responded to the Zenbleed vulnerability.

The reason for the change is straightforward: AI-assisted security research is finding kernel bugs faster than the old schedule could handle them. LLMs and automated agents are churning through kernel code and filing CVEs at a pace human researchers never matched. On top of that, the upstream Linux kernel community became its own CVE Numbering Authority and started assigning identifiers to thousands of bugs — many of which would previously have gone untracked. Linus Torvalds called this the "new normal" around the 7.0/7.1 release cycle, and Canonical is now adjusting its infrastructure to match.

## How the new cycle works

The two-week cycle runs in overlapping waves, which means a new kernel build lands roughly every week in practice:

- **Week one:** Patch selection and building. Candidates get pushed into the `-proposed` pocket.
- **Week two:** Testing on Ubuntu Certified hardware before the build moves to the stable release.

Teams that need fixes sooner can pull directly from `-proposed`, though those builds are untested. Canonical is also committing to publishing workarounds or hardening guidance within 24-48 hours of a CVE going public, ahead of a full patch.

The practical effect is that users on the standard release track get a new kernel roughly weekly, while the two-week structure preserves a testing window before anything lands in production.

## Questions this post answers

### When does Ubuntu's new unified two-week kernel update cycle start?

The unified two-week stable release update (SRU) cycle for Ubuntu kernel updates begins September 28, 2026. It replaces the previous split schedule where feature updates shipped every four weeks and security patches shipped separately every two weeks, consolidating both into one faster, more predictable cadence.

_Track upcoming Ubuntu kernel cadence changes on daily.dev before they hit your patch schedule._

### Why is Canonical changing its Ubuntu kernel security patch schedule?

Canonical is responding to a surge in CVE reports caused by AI-assisted vulnerability discovery tools finding bugs at scale, combined with the upstream Linux kernel community becoming its own CVE Numbering Authority and assigning identifiers to thousands of previously untracked bugs. The old four-week/two-week split schedule could not keep pace with this volume.

_Follow how AI-driven CVE discovery is reshaping patch cadences on daily.dev for systems you maintain._

### How fast will Canonical publish workarounds after a kernel vulnerability is disclosed?

Canonical aims to publish workarounds or hardening guidance within 24 to 48 hours of a public vulnerability disclosure, even before a full patch is ready. Users wanting fixes sooner can opt into the `-proposed` pocket, which carries untested updates ahead of the standard release.

_Check daily.dev for guidance timelines when triaging newly disclosed kernel vulnerabilities._

## Similar posts on daily.dev

- [CVE flood pushes Ubuntu onto weekly kernel release cycle](https://daily.dev/posts/cve-flood-pushes-ubuntu-onto-weekly-kernel-release-cycle-pa0z1gdyr) · The Register · 0 upvotes · 0 comments
- [The Linux Kernel Is Approaching 2,000 CVEs Per Release](https://daily.dev/posts/the-linux-kernel-is-approaching-2-000-cves-per-release-vzorlgrlg) · Phoronix · 0 upvotes · 0 comments
- [Linux CVE assignment process](https://daily.dev/posts/linux-cve-assignment-process-8whl1ct57) · Lobsters · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux), [#ubuntu](https://daily.dev/tags/ubuntu)

[View this post on daily.dev](https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Canonical speeds up Ubuntu kernel updates to keep pace with AI-driven CVE flood","url":"https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v"},"datePublished":"2026-09-24T02:28:34.034Z","dateModified":"2026-09-24T17:10:10.483Z","description":"Canonical is switching Ubuntu kernel updates to a unified two-week stable release update cycle starting September 28, 2026, replacing the prior split schedule...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/96b31bb703f9680cecf888a0685b2e72?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/96b31bb703f9680cecf888a0685b2e72?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux,ubuntu","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Canonical speeds up Ubuntu kernel updates to keep pace with AI-driven CVE flood"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/canonical-speeds-up-ubuntu-kernel-updates-to-keep-pace-with-ai-driven-cve-flood-ba99qjm4v#faq","mainEntity":[{"@type":"Question","name":"When does Ubuntu's new unified two-week kernel update cycle start?","acceptedAnswer":{"@type":"Answer","text":"The unified two-week stable release update (SRU) cycle for Ubuntu kernel updates begins September 28, 2026. It replaces the previous split schedule where feature updates shipped every four weeks and security patches shipped separately every two weeks, consolidating both into one faster, more predictable cadence. Track upcoming Ubuntu kernel cadence changes on daily.dev before they hit your patch schedule."}},{"@type":"Question","name":"Why is Canonical changing its Ubuntu kernel security patch schedule?","acceptedAnswer":{"@type":"Answer","text":"Canonical is responding to a surge in CVE reports caused by AI-assisted vulnerability discovery tools finding bugs at scale, combined with the upstream Linux kernel community becoming its own CVE Numbering Authority and assigning identifiers to thousands of previously untracked bugs. The old four-week/two-week split schedule could not keep pace with this volume. Follow how AI-driven CVE discovery is reshaping patch cadences on daily.dev for systems you maintain."}},{"@type":"Question","name":"How fast will Canonical publish workarounds after a kernel vulnerability is disclosed?","acceptedAnswer":{"@type":"Answer","text":"Canonical aims to publish workarounds or hardening guidance within 24 to 48 hours of a public vulnerability disclosure, even before a full patch is ready. Users wanting fixes sooner can opt into the `-proposed` pocket, which carries untested updates ahead of the standard release. Check daily.dev for guidance timelines when triaging newly disclosed kernel vulnerabilities."}}]}
```

