Linux Kernel Livepatch
Mitigate Linux kernel exploits
with Livepatch
Livepatch shrinks the exploit window for critical and high severity Linux kernel vulnerabilities, by patching the Linux kernel between security maintenance windows, while the system runs.
Livepatch provides security coverage for 10 years with Ubuntu Pro, and an additional five years with Ubuntu Pro's Legacy add-on, for a total of 15 years.
The benefits of Livepatch
Spend less time on unplanned work
Anyone that takes their security posture seriously applies critical and high security patches with urgency, outside their regularly scheduled patching maintenance window. This is work that impacts focus and distracts from goals and business objectives.
Livepatch reduces the unplanned work of installing Linux kernel security updates, making you more effective when managing Ubuntu systems.
Reduce downtime
Downtime is one of the major pains of every service provider, and it is unavoidable when deploying vulnerability fixes on the Linux kernel in the traditional way. That’s because the updated system needs to be rebooted, potentially disrupting Kubernetes, OpenStack, virtualized, or bare-metal workloads. Industry leaders avoid this problem and achieve high uptime by livepatching between scheduled maintenance windows.
Enhanced security
With early and cumulative patching of kernel vulnerabilities, Livepatch helps users maintain a strong security posture, and reduces the risk of exploits.
Follow organizational policy
Livepatch allows you to define your rollout policy and remain in full control of which machines will get updated and when, as well as provide updates to isolated network environments. System administrators can set a patching cut-off date and a patching delay on each machine, and uniformly secure groups of machines.
Ease of use
Livepatch is designed to be straightforward to set up and use, and patches are applied automatically after activation. Livepatch integrates with Canonical's web and API based Linux administration tool: Landscape.
Livepatch is used by
Kernel livepatching at a glance
When a high or critical Linux kernel vulnerability is detected a livepatch along with a Livepatch Security Notice are issued. Systems that enable the livepatch client will receive and apply the patch, after it is made available. The livepatch will provide new kernel code replacing the vulnerable one, and will update the rest of the kernel to use the new code.
Livepatch on-prem overview
Livepatch on-prem is designed for air-gapped environments where Livepatch Client is unavailable to access security endpoints in Canonical's cloud. Livepatch on-prem can be updated with the latest patches, and Livepatch Client can retrieve the updates from Livepatch on-prem, instead of Canonical's cloud.
What our customers say
“Livepatch is a perfect fit for our needs. There’s no other solution like it, and it’s highly cost-effective. Manually migrating virtual machines, applying kernel updates, and rebooting took an average of 32 hours per server. Multiplied by 80 servers, that was more than 2,500 hours of work.”
Shinya Tsunematsu
Senior Engineering Lead
Tech Division, GMO Pepabo
“Livepatch is like a dream come true, both from a technical and a business standpoint. Our Ubuntu systems now rarely, or never, have to be rebooted. Service is continuous. That makes a big difference for user and customer satisfaction and loyalty.”
Masaaki Hirose
IT Platform Department
DeNA