EOSL Alerts

Ubuntu 22.10 Kinetic Kudu EOL July 20, 2023 Action Plan

Updated 3rd Party Support Team

What Happens on July 20, 2023

Ubuntu 22.10 'Kinetic Kudu' reaches end of life on July 20, 2023. After that date, Canonical will no longer release security patches, bug fixes, or updates of any kind for this release. Your systems will continue to run, but every newly discovered vulnerability will remain unpatched. Vendor support cases will be closed, and service-level agreements will no longer apply.

Because 22.10 is not an LTS release, it followed Ubuntu's standard nine-month support window. Organizations that deployed Kinetic Kudu for development, testing, or short-term production workloads now face a hard deadline with limited time to act.

Why a Full Migration Is No Longer Realistic

Three months is not enough time for most IT teams to complete a full operating-system migration across an enterprise estate. Change-control processes, application compatibility testing, user-acceptance testing, and scheduled maintenance windows all require lead time that no longer exists. Rushing a migration increases the risk of service disruption and introduces new vulnerabilities through incomplete testing.

The pragmatic approach is to acknowledge the constraint and focus on risk management, not emergency cutover.

Your Week-by-Week Action Plan

Weeks 1–2: Inventory and Classification

Identify every system running Ubuntu 22.10 in your environment. Use configuration-management databases, asset-management tools, or automated scanning to build a complete list. For each system, document:

  • Hostname and IP address
  • Role and criticality (production, development, test)
  • Applications and services hosted
  • Network exposure (internet-facing, internal only, isolated)
  • Data classification (PCI, PHI, PII, proprietary, public)

Rank systems by business impact and regulatory exposure. This inventory will drive every decision in the weeks ahead and will be essential for audit and compliance documentation.

Weeks 3–4: Isolate and Harden

For systems that cannot be migrated before July 20, implement defensive layers:

  • Remove or disable unnecessary services and open ports
  • Apply the latest available patches while vendor support is still active
  • Segment systems behind firewalls with strict ingress and egress rules
  • Enable verbose logging and configure log forwarding to a central SIEM
  • Remove direct internet access where possible; route traffic through authenticated proxies
  • Disable or lock unused user accounts and enforce key-based authentication

These measures will not prevent exploitation of future zero-day vulnerabilities, but they reduce the attack surface and improve your ability to detect intrusions.

Weeks 5–6: Document Risk and Exposure

Prepare a formal risk assessment for leadership, auditors, and cyber-insurance carriers. Include:

  • Total number of Ubuntu 22.10 systems remaining in service after July 20
  • Business justification for continued operation (cost, complexity, application dependencies)
  • Compensating controls in place (network isolation, monitoring, third-party support)
  • Projected timeline for full migration to a supported release
  • Estimated financial and operational impact of a security incident

This documentation demonstrates due diligence and provides a defensible audit trail. In the event of a breach, it shows that you understood the risk and took reasonable steps to mitigate it.

Weeks 7–9: Secure Third-Party Support

Third-party support providers can deliver security patches, bug fixes, and technical assistance for Ubuntu 22.10 after Canonical's support ends. These vendors maintain their own patch repositories, monitor CVE databases, and backport fixes for end-of-life releases.

A third-party support contract should be in place on July 20—not negotiated afterward. Procurement, legal review, and vendor onboarding all take time. Start the process now so that your systems are covered the day vendor support expires.

Key questions to ask prospective vendors:

  • What is the patch release cadence for critical and high-severity vulnerabilities?
  • Do you provide 24/7 incident response and technical support?
  • Can you deliver patches through a private repository that integrates with our existing deployment tools?
  • What SLA terms cover response time and patch delivery?
  • Do you support compliance frameworks relevant to our industry (PCI-DSS, HIPAA, SOC 2)?

Week 10–12: Prepare for Day One After EOL

In the final weeks before July 20, ensure your operational readiness:

  • Confirm that third-party support is active and repository access is configured
  • Update incident-response playbooks to reflect the new support contact
  • Notify application owners and business stakeholders of the support transition
  • Schedule a post-EOL review to evaluate patch delivery and support responsiveness
  • Continue to advance your migration timeline for a planned cutover in the coming months

What Third-Party Support Provides

Third-party maintenance is not a workaround or a hack. It is a standard practice in enterprise IT for managing lifecycle transitions. When vendor support ends, third-party providers step in to deliver:

  • Security patches for newly disclosed vulnerabilities
  • Bug fixes and stability updates
  • Technical support from engineers who specialize in the platform
  • Compliance attestation for audits and regulatory reviews

This allows you to maintain security and operational stability while you complete a controlled migration on your own schedule, not the vendor's.

Moving Forward

July 20, 2023 is not a disaster date—it is a known deadline that requires a rational response. By inventorying your systems, isolating and hardening them, documenting your risk posture, and securing third-party support, you can operate safely and compliantly past the vendor EOL date.

If you are running Ubuntu 22.10 in production and need support after July 20, contact our team to discuss your options. We provide third-party support for Ubuntu and other enterprise Linux distributions, with patch delivery, technical assistance, and compliance support tailored to your environment.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep Ubuntu 22.10 'Kinetic Kudu' running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

Ubuntu software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.