Canonical Brings Ubuntu Livepatch to Arm64
Canonical says Ubuntu Livepatch now supports Arm64, starting with Ubuntu 26.04 LTS and Ubuntu Core 26 coverage boundaries for supported kernels.
Canonical has extended Ubuntu Livepatch to Arm64, giving Ubuntu’s Arm-based edge and cloud systems a rebootless path for selected critical kernel fixes.
Table Of Content
Canonical announced the Arm64 expansion on Tuesday, saying Ubuntu on an Arm64 machine can now apply critical kernel updates without service interruption or a reboot. The company says the new support starts with Ubuntu Core 26 for Arm64, while its existing AMD64 coverage continues for Ubuntu Core 20 and later.
The move is narrow but important. Live kernel patching is not a replacement for every kernel upgrade or every reboot. It is a way to reduce the exploit window for security issues that Canonical can safely patch in memory, especially on systems that cannot be interrupted whenever a kernel vulnerability lands.
Arm64 moves from exception to supported Livepatch target
Arm servers and edge devices have become more common in production infrastructure, from cloud instances to remote appliances and industrial systems. Those systems often run in places where maintenance windows are expensive, hard to coordinate, or simply too frequent for traditional reboot-first patching.
Canonical’s announcement says the company had to close several technical gaps before Arm64 could be treated like a first-class Livepatch target. In 2023, its gap analysis found that the upstream Arm64 ecosystem still lacked pieces needed for safe live kernel patching, including reliable stack-trace support and mature Arm64 handling in the supporting toolchain.
The company says those prerequisites have since landed upstream, allowing its Livepatch server, client, build infrastructure, and regression tests to handle Arm64 patches. Canonical also says it expanded native Arm64 build farms rather than relying on architecture emulation, because live kernel patches need to be built and tested on target architectures for correctness and performance.
The support boundary matters
Canonical’s covered-kernels matrix lists Ubuntu 26.04 LTS on arm64 with the 7.0 GA kernel and variants including generic and major cloud flavors. The same Canonical page says Livepatch will provide ARM64 architecture coverage from release 26.04, and that older releases are not covered for ARM64 because of limitations in tooling available in those releases.
That is the practical boundary operators should notice. The announcement broadens Ubuntu Livepatch to Arm64, but it does not mean every older Arm board, appliance image, or custom kernel suddenly receives patches. Fleets still need an inventory of Ubuntu release, kernel ABI, kernel flavor, architecture, and Livepatch support status.
Why this is security automation, not magic
Canonical’s Livepatch product page describes the service as a way to patch high and critical Linux kernel vulnerabilities while the system runs, reducing downtime between regular maintenance windows. It also stresses a key point: Livepatch targets kernel vulnerabilities that are practical to patch safely in memory, not every userspace library or every possible update.
For hosting providers, Kubernetes operators, appliance vendors, and internal platform teams, that distinction is useful. Livepatch can reduce emergency reboot pressure when a critical kernel issue appears, but administrators still need regular kernel upgrades, scheduled reboots, vulnerability tracking, and configuration management for the rest of the stack.
The operational gain is in cadence. If an Arm64 fleet sits at the edge of a network or runs customer workloads that resist interruption, teams can apply qualifying kernel fixes sooner and reserve disruptive reboots for planned maintenance windows.
What administrators should check next
The Ubuntu Pro Client documentation says Livepatch is managed through Ubuntu Pro and that administrators can check service status after attaching a subscription. It also warns that unsupported kernels can enable the service but will not receive updates if Canonical does not support that kernel for Livepatch.
That makes validation the next step for Arm64 deployments. Teams should verify whether their devices are on Ubuntu 26.04 LTS or Ubuntu Core 26, whether the running kernel appears in Canonical’s supported matrix, whether the Livepatch client reports a healthy state, and whether their internal maintenance policy still includes periodic full kernel upgrades.
For mixed fleets, the rollout should also separate AMD64 and Arm64 assumptions. Existing x86 Livepatch procedures may transfer operationally, but support windows, kernel variants, and device-image constraints need to be checked architecture by architecture.
The bigger signal for edge Linux
Canonical’s Arm64 Livepatch support is another sign that Arm-based Linux infrastructure is no longer a special case. Edge AI devices, cloud Arm instances, and compact appliances are now expected to meet the same availability and security expectations as traditional server fleets.
Livepatch does not remove the need for disciplined maintenance. It changes the timing of risk. By making selected kernel fixes available without an immediate reboot on supported Arm64 Ubuntu systems, Canonical is giving operators one more tool to keep distributed Linux fleets patched while they wait for the next safe maintenance window.








No Comment! Be the first one.