Canonical is speeding up Ubuntu's kernel updates because it's drowning in AI-discovered bugs

Canonical is speeding up Ubuntu's kernel updates because it's drowning in AI-discovered bugs

Published Sep 23, 2026, 10:24 PM EDT Simon is a Computer Science BSc graduate who has been writing about technology since 2014, and using Windows machines since 3.1. After working for an indie game studio and acting as the family's go-to technician for all computer issues, he found his passion for writing and decided to use his skill set to write about all things tech. Since beginning his writing career, he has written for many different publications such as WorldStart, Listverse, and MakeTechEasier. However, after finding his home at MakeUseOf in February 2019, he would eventually move on to its sister site, XDA, to bring the latest and greatest in Windows, Linux, and DIY electronics. Summary LLMs have massively increased CVE reports, overwhelming maintainers. Canonical now bundles updates into a unified two-week cycle to handle the flood. It mirrors the Linux kernel's recent discovery of a "new normal" for AI-generated bug reports. Whether or not LLMs belong in an open-source project, whether they're used for content generation or for finding bugs, is an ongoing debate within the FOSS scene right now. Some communities have banned it, while others have adopted the new tech, although they've had to adapt to a new way of doing things. Such is the case with Canonical, which has announced a new two-week unified patch cycle for Ubuntu because LLMs can't stop finding bugs in the kernel. Canonical squashes its Ubuntu update cycle into a two-week cycle There are just too many reports coming in Credit: Canonical As spotted by OMG Ubuntu, Canonical has announced its new update cycle. It reveals that maintainers have recently been swamped with more Common Vulnerabilities and Exposures reports (CVEs) than ever before, and there's no prize for guessing why: The recent explosion in the volume of CVEs is fueled by artificial intelligence: large language models (LLMs) and specialized AI agents have transformed bug discovery from a manual, time-intensive process into a highly automated engine. Additionally, the upstream kernel community became its own CVE Numbering Authority (CNA) and assigned CVE (Common Vulnerabilities and Exposures) identifiers to thousands of bugs, arguing that at the kernel level, almost any type of bug that can affect a running system, could potentially be classified as a vulnerability. This, in turn, has prompted developers to speed up the process of getting patches out the door. Right now, they're swamped with CVEs, so they're moving away from a regular update every four weeks and a security patch every two weeks. Now, everything's getting bundled into one big two-week update cycle, and you can see its timeline in the chart above. Maintainers drowning in LLM-discovered issues is by no means new It has been a constant presence for the Linux kernel recently The thing is, Ubuntu is by no means an outlier here. The Linux kernel itself has been wading through a sea of bug reports recently, and it doesn't seem like it'll die down any time soon. We first saw signs that something was amiss back during the Linux 7.0 release candidates. Linus Torvalds noticed a spike in the number of bug reports, which made each release candidate larger than they usually are; however, the bugs being found weren't serious ones, which didn't justify delaying 7.0's release. Torvalds would go on to release 7.0 on time. Things came to a head in the Linux 7.1 release, when Torvalds realized 7.0 was not a fluke, and the release candidates were still really big. Even worse, bug reports were coming in that either used secure channels for menial changes or duplicated other bug reports, making it "almost entirely unmanageable." Torvalds chalked this trend up to AI assistants automatically spotting, reporting, and fixing bugs, which ended up in larger changelists than before. Torvalds would crown this "the new normal," and has since adapted to handle the influx, much like how Canonical is feeling out its own "new normal" right now.

Original Source

Read the full article at Xda-developers →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.