"Large language models (LLMs) and specialized AI agents have transformed bug discovery from a manual, time‑intensive process into a highly automated engine," Canonical said on Wednesday.
Canonical moves to overlapping two‑week SRU cycles and weekly kernel releases
Canonical is changing how Ubuntu ships kernel Stable Release Updates (SRUs). The company is replacing its current cadence — a four‑week regular cycle and a two‑week security cycle — with overlapping two‑week cycles that start one week apart. Because a new SRU cycle begins every week, Canonical will be able to publish a kernel release each week.
Under the new system, each SRU cycle lasts two weeks. The first week focuses on integrating patches, preparing and building kernel packages, and running basic checks; by the end of that stage release candidates are published to Ubuntu's -proposed pocket. The second week is reserved for more extensive work: hardware certification, distribution integration, and regression testing. Once that testing completes, the kernel is released. Because the next cycle begins while the second‑week testing is still under way, Canonical can publish another kernel the following week.
AI and the CVE flood that pushed the change
Canonical attributes the schedule overhaul to a sharp rise in reported vulnerabilities. The company specifically credits AI — "LLMs and specialized AI agents" — with transforming bug hunting from a slow, manual effort into an automated engine that uncovers flaws much faster than before. That acceleration has contributed to what Canonical describes as a backlog of vulnerabilities that needs faster patch delivery.
AI is not the only cause. The upstream Linux kernel community became a CVE Numbering Authority in 2024 and began assigning identifiers to thousands of bugs on the basis that nearly any kernel flaw affecting a running system could have security implications. Canonical says the combination of automated discovery and broader CVE assignment has raised the volume of CVEs Linux vendors must handle, creating pressure to shorten the interval between disclosure and patched kernels reaching users.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogOptions and trade‑offs for administrators and sensitive organizations
Canonical acknowledges a trade‑off between speed and the depth of vendor testing. Organizations particularly sensitive to patching delays can take release candidates from the -proposed pocket after the first week and run their own acceptance tests. That approach can make kernel CVE fixes available within a week, but it places more testing responsibility on the customer and delivers fixes "before the company has finished its extensive certification testing," Canonical says.
Canonical frames that choice clearly: customers who accept release candidates faster gain earlier access to fixes, at the cost of bypassing Canonical's full hardware certification and regression testing.
Mitigations Canonical will provide during the disclosure-to-patch window
To reduce exposure between public disclosure and patch availability, Canonical says it will try to provide safe workarounds where possible, or recommend general hardening measures when no workaround exists. The company aims to put systems into what it calls a "defensible, safer state" within 24 to 48 hours of public disclosure. Canonical emphasizes these measures are not a substitute for patching but are intended to give administrators an alternative to "crossing their fingers" while fixes move through the release process.
What this means for technologists, security teams, and affected enterprises
- Technologists and security teams: Expect a busier kernel release rhythm and to monitor Ubuntu's -proposed pocket closely. Teams that prioritize rapid patching will need capacity to run acceptance tests on release candidates and decide whether to deploy pre‑certified fixes.
- Affected enterprises and procurement leaders: Organizations sensitive to patch windows can opt to accept earlier release candidates, but they must weigh faster fixes against the absence of Canonical's full certification and regression testing.
- End users and general operations: Administrators should watch for Canonical's published safe workarounds and hardening recommendations, which the company intends to provide within 24–48 hours of disclosure, while keeping in mind that such measures do not replace eventual patching.
The net effect, Canonical says, is a "considerably busier kernel release schedule" — a response to machines finding bugs faster than humans can patch them. The company has adjusted its pipeline to publish more frequently, offered an accelerated path for customers willing to test release candidates themselves, and promised interim mitigation guidance within two days of disclosure. Whether the overlapping two‑week SRU cadence will be enough to keep pace with AI‑driven discovery and the expanded CVE workload assigned upstream remains the central operational question Canonical has set out to answer.




