EOSL Alerts

Ubuntu 25.04 End of Life Action Plan: Jan 17, 2026 Deadline

Updated 3rd Party Support Team

Introduction

Canonical’s Ubuntu 25.04 (codenamed ‘Plucky Puffin’) reaches end of life (EOL) on January 17, 2026. This is not a long-term support (LTS) release, meaning no further security patches, bug fixes, or vendor-provided support after that date. With only about three months left, a complete migration to a supported release may no longer be realistic for many estates—but that doesn’t mean you have to accept risk.

This article lays out a clear, week-by-week action plan to manage the transition, harden remaining systems, and ensure business continuity.

What Changes on January 17, 2026

On the EOL date, Canonical will stop producing updates for Ubuntu 25.04. This means:

  • No security patches for newly discovered vulnerabilities.
  • No bug fixes for software or kernel issues.
  • No vendor support—Canonical will not answer tickets or offer guidance for this release.

Systems still running Ubuntu 25.04 after January 17 will be exposed to any vulnerabilities that emerge. Compliance frameworks, auditors, and cyber-insurance policies often require a clear remediation plan for EOL software.

Why Full Migration Is No Longer Realistic

A typical OS migration project for a medium-sized estate takes several months—planning, testing, application compatibility checks, and phased rollout. If you haven’t started by now, you almost certainly cannot complete a clean migration before January 17. That’s not a failure; it’s a reality many IT teams face with non-LTS releases that have short support windows.

Instead of scrambling, focus on what can be done in the remaining time to reduce risk and maintain operational integrity.

The Remaining Three Months: A Week-by-Week Action Checklist

Weeks 1–2: Inventory and Assess

  • Identify every system running Ubuntu 25.04. Use configuration management or asset discovery tools.
  • Classify each instance by criticality: production, staging, internal tools, development.
  • Determine whether each workload can be upgraded to a supported release (e.g., Ubuntu 24.04 LTS) or if it must remain on 25.04 for compatibility reasons.
  • Document dependencies—shared libraries, custom scripts, third-party applications that may not work on a newer kernel or library versions.

Weeks 3–4: Isolate and Harden

  • For systems that cannot be migrated before EOL, restrict network access: place them behind firewalls, VLANs, or jump boxes.
  • Disable unnecessary services and remove unused packages.
  • Apply all existing security patches from Canonical before the EOL date. (Patches will stop on January 17, 2026.)
  • Review and tighten local firewall rules (e.g., ufw).
  • Enable enhanced logging and monitoring for these systems.

Weeks 5–6: Document for Auditors and Insurers

  • Create a formal risk register listing each EOL system and its compensating controls.
  • Note the planned transition date or justification for continued use (e.g., “system will be replaced in Q2 2026”).
  • Ensure your documentation matches the language required by your compliance framework (PCI DSS, SOC 2, HIPAA, etc.) and cyber-insurance policy.
  • Get sign-off from management or the risk owner for accepting the extended use.

Weeks 7–8: Secure Support and Final Testing

  • Evaluate third-party maintenance providers that offer continued security patches and support for EOL Ubuntu releases. A contract arranged before January 17 ensures you have coverage on day one after EOL.
  • Test any patches or fixes from your chosen provider in a staging environment.
  • Update your change management and disaster recovery plans to reflect the EOL status.

Weeks 9–12: Execute and Monitor

  • Apply any remaining updates from Canonical before the EOL date.
  • Verify that isolation and hardening measures are in place.
  • Perform a final audit to ensure no unplanned systems are left running Ubuntu 25.04 without controls.
  • Set up automated monitoring to alert on any attempted exploits or unusual behaviour.
  • Communicate the EOL state and mitigation plan to stakeholders and end users.

What About the Missing Patches?

After January 17, Canonical will no longer release patches for Ubuntu 25.04. Any critical vulnerability discovered in the kernel, OpenSSL, systemd, or other core components will remain unpatched by the vendor.

However, third-party support organisations do provide backported security patches for EOL Ubuntu releases. They maintain private patch repositories and can respond to CVEs just as a vendor would—often with faster SLAs. This is not a free option, but it is significantly cheaper than a forklift upgrade and can extend the useful life of your current deployment while you plan a proper migration.

Third-Party Support Keeps Ubuntu 25.04 Safe After EOL

If you cannot migrate every instance before January 17, you don’t have to accept an unpatched gap. Third-party maintenance (TPM) providers can supply ongoing security fixes, technical support, and access to a patch repository for Ubuntu 25.04 long after Canonical stops.

By engaging a TPM provider now, you:

  • Maintain compliance with auditors and insurers.
  • Avoid forced upgrades on your own timeline.
  • Reduce risk from unpatched CVEs.
  • Free up staff to focus on longer-term modernisation rather than emergency migrations.

To learn how third-party support can cover your Ubuntu 25.04 systems after EOL, contact our team today.

Summary

Ubuntu 25.04 ‘Plucky Puffin’ ends vendor support on January 17, 2026. Full migration before that date is unlikely for many organisations, but inaction is not an option. Use the remaining weeks to inventory, isolate, harden, and document your fleet. Then secure third-party support to ensure continued patching and compliance. With a structured plan, you can manage the EOL transition without panic.

For further details on Ubuntu lifecycles, see the official lifecycle page or check endoflife.date/ubuntu.

How we can help

Keep it supported after end of life

The vendor's date doesn't have to be yours. Our engineers keep Ubuntu 25.04 'Plucky Puffin' running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.

Ubuntu software support →

Migration services

When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.

Migration & hybrid cloud services →

24×7 remote administration

Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.

24/7 operations & remote administration →

Talk to a support specialist

Speak with an engineer, not a sales rep. We respond within 24 hours.

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.