Back Theregister CVE flood pushes Ubuntu onto weekly kernel release cycle
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
Decades-old file security flaws found in Android, Linux, macOS, and Windows 23 minutes ago
Decades-old file security flaws found in Android, Linux, macOS, and Windows
Someone went shopping in ASUS's eShop – for customer data 2 hours ago
Someone went shopping in ASUS's eShop – for customer data
Google to critical infra orgs: Our AI scanners won't be evil, promise 4 hours ago
Google to critical infra orgs: Our AI scanners won't be evil, promise
Government contractor exposed path to immigration records 8 hours ago
Government contractor exposed path to immigration records
OpenAI agents ‘infiltrated Australian government website’ 17 hours ago
OpenAI agents ‘infiltrated Australian government website’
Canonical is speeding up Ubuntu kernel releases to one a week as AI-assisted bug hunting helps bury defenders under an ever-growing pile of CVEs.
The Ubuntu maker is overhauling how it ships kernel Stable Release Updates (SRUs), replacing its current four-week regular and two-week security cycles with overlapping two-week cycles that will push a kernel release every week.
Canonical says the change is needed because the number of reported vulnerabilities has exploded, with AI deserving some of the credit – or blame, depending on which side of the patch queue you're sitting.
"Large language models (LLMs) and specialized AI agents have transformed bug discovery from a manual, time-intensive process into a highly automated engine," Canonical said on Wednesday.
AI isn't solely responsible for the CVE avalanche. The upstream Linux kernel community became a CVE Numbering Authority in 2024 and began assigning identifiers to thousands of bugs on the basis that almost any kernel flaw affecting a running system could have security implications.
Put the two together, and Linux vendors have far more CVEs to deal with. Canonical says the resulting backlog requires faster releases to shrink the window between vulnerabilities becoming public and patched kernels reaching users.
Under the new system, each SRU cycle lasts two weeks, but a new one starts every week. The first week is spent integrating patches, preparing and building kernel packages, and carrying out basic checks to make sure nothing catches fire. By the end of that stage, release candidates are published to Ubuntu's -proposed pocket.
Week two is reserved for the heavier stuff, including hardware certification, distro integration, and regression testing. Once that's done, the kernel is released. Because the cycle starts while that testing is under way, Canonical can publish another kernel the following week.
For admins who consider even that too leisurely, there's a faster route.
Organizations particularly sensitive to patching delays can take release candidates from the -proposed pocket after the first week and run their own acceptance tests. Canonical makes the trade-off clear: those users get access to fixes sooner, but before the company has finished its extensive certification testing.
That can make kernel CVE fixes available within a week, provided customers are willing to perform some of the testing themselves.
Canonical also wants to leave customers less exposed between disclosure and patch availability. It aims to provide safe workarounds where possible, or recommend general hardening measures where none exist, putting systems into what it calls a "defensible, safer state" within 24 to 48 hours of public disclosure.
Those measures are not intended to replace patching, merely to give admins something better than crossing their fingers while a fix makes its way through the release process.
The end result is a considerably busier kernel release schedule, although perhaps that's inevitable when machines are increasingly being enlisted to find bugs faster than humans can patch them.
AI was supposed to make everyone's jobs easier. Ubuntu's kernel team may want a word. ®
Decades-old file security flaws found in Android, Linux, macOS, and Windows
Security researchers report that Microsoft considers the side-channel leak of file events to be by design
iPhone 18 Pro benchmark boosted by giving it a cold drink
3x the vapor-chamber surface area can only do so much; luckily the fridge helped with sustained performance
HPE makes its “unified storage” claim real as B10000 R6 hits GA
PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity
CVE flood pushes Ubuntu onto weekly kernel release cycle
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
In the age of AI, teaching networking principles remains more important than learning protocols
Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it
AI boom could wipe 230 million budget phones a year from the market
Sub-$200 shipments forecast to shrink 40% by 2030 as component costs climb
Anthropic decides to support OpenAI's markdown instructions spec
Anthropic decides to support OpenAI's markdown instructions spec
Microsoft agentically ports Copilot runtime to Rust for $120K
Microsoft agentically ports Copilot runtime to Rust for $120K
KPMG tech cuts come with a severance sum some staff call insulting
KPMG tech cuts come with a severance sum some staff call insulting
on call Techie fixed Wi-Fi dead zone with a drill
Techie fixed Wi-Fi dead zone with a drill
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
Researchers find way to listen in on headphones from afar
Researchers find way to listen in on headphones from afar
CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
CVE flood pushes Ubuntu onto weekly kernel release cycle
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
Google to critical infra orgs: Our AI scanners won't be evil, promise Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
Google to critical infra orgs: Our AI scanners won't be evil, promise
Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
Shut up and calculate: Jev's new AI primitives for coders Developers test what they can build with TypeSafe's fast, typed decision model
Shut up and calculate: Jev's new AI primitives for coders
Developers test what they can build with TypeSafe's fast, typed decision model
Frontier AI keeps racing despite calls to slow down Anthropic and OpenAI debut Opus 5.5 and GPT-6 Sol and Luna
Frontier AI keeps racing despite calls to slow down
Anthropic and OpenAI debut Opus 5.5 and GPT-6 Sol and Luna
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions 'first' publicly documented Windows implant to use LLMs for C2
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
'first' publicly documented Windows implant to use LLMs for C2
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user
KDE turns 30 and someone's brought an AI-native desktop proposal
Akademy talk imagines Plasma assembling itself around a personal model of each user
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
