# What changed Canonical is changing how it ships kernel Stable Release Updates (SRUs) for Ubuntu. The previous model used a split cadence introduced in 2023: a full kernel update every four weeks with an urgent security update available two weeks later. That model is being replaced by a single two-week SRU cycle. Because each two-week cycle overlaps with the next, fixes will effectively arrive on a weekly basis.
# Why the shift Canonical describes a rapid rise in reported kernel bugs and CVEs driven largely by researchers using AI models and agents to find issues. With flaws being discovered faster than before, the company concluded that kernel patching, testing and release processes needed to move faster to avoid leaving users exposed.
# How the new two-week SRU works
- Week one: engineers integrate patches, build kernel packages and run initial smoke tests. Candidate builds are pushed to Ubuntu's -proposed pocket for wider testing.
- Week two: testing and certification complete, and stable updates are released to supported systems.
This repeating two-week cadence, with a new cycle starting one week into the previous one, produces a continuous stream of releases that amounts to weekly kernel fixes in practice.
# Options for faster protection If you need updates sooner than Canonical's testing finishes, you can enable the -proposed pocket to receive candidate kernel builds earlier. Canonical warns this carries risk because -proposed contains release candidates that have not gone through full certification.
For urgent threats where a safe patch isn't yet available, Canonical aims to provide or document workarounds within 24–48 hours of a vulnerability being identified. If no specific workaround exists, it will offer general hardening steps to help make environments safer until a patch ships.
# What this means for different users
- Desktop users: will receive fixes more frequently with the option to test -proposed builds if they accept risk. For most desktop installations, stable releases remain the default.
- Security teams: should expect higher throughput of disclosed CVEs and plan triage, testing, and deployment processes accordingly.
# Practical next steps
- Audit current update channels and decide whether to stay on stable SRUs or enable -proposed for faster delivery in controlled environments.
- Update triage playbooks to handle a higher volume of kernel CVEs and incorporate the 24–48 hour workaround guidance into incident response plans.
- For production systems, consider staged deployments and automated testing to cope with a quicker release cadence.
# Bottom line Canonical's unified two-week kernel SRU cycle responds to a flood of vulnerabilities being found faster than defenders can patch. The new flow accelerates integration, testing and release so fixes reach users more often, while offering documented short-term mitigation steps and an opt-in path to earlier candidate builds for those who accept extra risk.