Security News

Ubuntu Moves to Weekly Kernel Patches as AI-Driven Bug Discovery Overwhelms Defenders

The Register · 25 Sept 2026
Key Takeaway Australian SMBs running Ubuntu systems should ensure automatic updates are enabled and review patching schedules, since faster kernel releases mean more frequent updates to track and apply.

Canonical, the company behind Ubuntu, is changing how it ships kernel security updates in response to a surge in reported vulnerabilities. It is replacing its current four week regular and two week security update cycles with overlapping two week cycles, effectively delivering a new kernel release every week.

Canonical says AI is a major driver of this change. Large language models and specialised AI agents have made it far easier to automatically discover bugs, generating vulnerability reports at a pace defenders struggle to keep up with. This has been compounded by the Linux kernel community becoming an official CVE Numbering Authority in 2024, which led to many more kernel bugs being assigned identifiers. Together, these factors have created a growing backlog that Canonical says requires faster patch delivery to close the gap between a vulnerability being disclosed and a fix reaching users.

Under the new process, each two week cycle overlaps with the next: the first week covers patch integration and basic checks, while the second involves deeper testing such as hardware certification and regression checks. Organisations that need fixes faster can pull release candidates after week one and run their own testing, though Canonical notes this means using kernels before its full certification process is complete.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.