Canonical is changing how Ubuntu kernel updates are delivered. According to Help Net Security, the company is merging its four-week Stable Release Update cycle and its two-week security fix cycle into a single two-week cycle. Because each cycle begins one week after the previous one, updates effectively ship on a weekly basis.
Under the new timetable, Canonical snapshots the kernel tree at a cutoff date, builds kernels and runs smoke tests in week one, then puts those builds in the -proposed pocket. Week two is spent on certification, integration and regression testing on certified hardware before release. Canonical ties the change to the rise in CVE disclosures: LLMs and AI agents have automated bug hunting, and the upstream kernel community has become a CVE Numbering Authority, assigning identifiers to thousands of kernel bugs.
Canonical says expedited releases are not possible while thoroughly testing every release candidate, so teams that need a fix sooner can pull release candidates from -proposed and run their own acceptance tests. Those builds have not gone through certification, so any regressions they carry become the adopter's responsibility. Canonical also plans to publish workarounds within 24 to 48 hours of public disclosure when a safe one exists, otherwise directing users to general hardening steps.