CANONICAL is changing Ubuntu’s stable kernel update process in response to the growing volume of vulnerability reports. Instead of a standard four-week cycle, with separate two-week emergency security releases, it plans to use overlapping two-week Stable Release Update (SRU) cycles. Each kernel will still undergo two weeks of validation: packages and basic boot checks are completed during the first week, followed by hardware certification, integration testing and regression analysis in the second. Because cycles will begin one week apart, validated kernels should become available weekly without reducing the testing period.
The transition is scheduled to begin on 28 September 2026, with further cycles starting on 12 October. Canonical plans to activate the overlapping process on 26 October. The company attributes the pressure partly to AI-assisted vulnerability discovery and to kernel.org becoming a CVE Numbering Authority in February 2024, which increased the number of recorded potential issues.
An Ubuntu Azure kernel update issued on 22 September listed more than 1,400 addressed CVEs, although the article notes that many CVEs may not apply to particular systems because they use only a small part of the kernel. It also says that some Linux vulnerabilities are actively exploited, but does not identify them.
Administrators needing fixes sooner can use candidate packages from the `-proposed` repository after the first week and perform their own acceptance testing, accepting responsibility for validation. Canonical also intends to provide temporary mitigations or hardening guidance where possible, targeting a more secure state within 24 to 48 hours of a critical disclosure. These measures are not intended to replace the final kernel update.