• Sources: primary, discussion
  • Summary: Canonical replaces the separate four-week regular and two-week security kernel cadences with overlapping two-week SRU cycles that publish weekly. The post names LLM-assisted bug discovery and the kernel community becoming its own CNA as the reasons CVE volume outgrew the old cadence.
  • Why it matters: Ubuntu fleets get kernel CVE fixes weekly instead of on two separate cadences, which changes reboot and validation scheduling for anyone running Ubuntu kernels at scale.
  • Follow-up: Track the first cycles under the new cadence and whether regression rates move with the shorter SRU window.

send feedback on this story