Trending: On-device modelsSearch
iHeartGeek
iTECH

Ubuntu 26.10 strips back Secure Boot and moves coreutils to Rust

Ubuntu's interim release cuts parsers out of the Secure Boot chain, brings TPM-backed encryption to machines without a hardware root of trust, and finishes the move of coreutils to Rust.

Canonical's blog card for the article: the Canonical logo above the headline “What’s new in security for Ubuntu 26.10?” and the line “Advancing memory safety, reducing attack exposure, and more”, with a grey Ubuntu swirl graphic on the right.

Ubuntu 26.10 takes a harder line on how much code runs before the kernel. Canonical's security write-up for the release, published on 6 October, sets out a signed GRUB pruned back to the filesystems Ubuntu actually boots from, TPM-backed disk encryption extended to machines without a hardware root of trust, and core utilities that now run entirely on Rust.

A smaller Secure Boot path

The signed GRUB in 26.10 keeps only what Ubuntu needs: /boot on ext4, FAT and ISO9660, plus squashfs for snaps. Gone from the signed build are the filesystem drivers for Btrfs, HFS+, XFS and ZFS, the JPEG and PNG image loaders, and Apple partition tables. Booting from LVM volumes, software RAID other than RAID1, or a LUKS-encrypted /boot is no longer supported with Secure Boot enabled.

Only the boot path is affected. LVM, RAID, LUKS, Btrfs and ZFS all still work once the system is running, and turning Secure Boot off restores the full feature set. Canonical made the change immediately after a long-term support release for a reason: anyone who depends on the removed options can stay on Ubuntu 26.04 LTS until May 2041 with Ubuntu Pro and the Legacy add-on.

TPM encryption, and the PIN you now need

TPM-backed full-disk encryption ties automatic unlocking to a system's measured boot state. In 26.10 it reaches machines without a hardware root of trust, where the firmware cannot be verified automatically. Administrators have to set a PIN on those systems, and Canonical is explicit that removing it later gives up protection against firmware tampering. Machines with a hardware root of trust — most PCs built since 2021 — still unlock on their own. fwupd has also been taught to ask for a recovery key only when a firmware update could actually disturb the measurements that unlock the disk, a fix backported to 26.04 LTS.

Rust coreutils, OpenSSL 4.0 and the rest

Ubuntu 26.04 LTS made the Rust uutils coreutils the default but kept GNU's cp, mv and rm for compatibility. 26.10 finishes the job, so the default core utilities are now entirely Rust — safe Rust rules out use-after-free and out-of-bounds access at compile time, though not logic errors or unsafe code. Canonical suggests testing scripts that lean on subtle command behaviour, particularly privileged workflows that copy, move or delete files.

The release moves to OpenSSL 4.0, the first new major version since 3.0. It adds Encrypted Client Hello, which hides the inner TLS ClientHello including the requested server name when an application and server both support it, and it keeps ML-KEM, ML-DSA and SLH-DSA available with hybrid post-quantum key exchange preferred by default. A new system-level tool called upki handles certificate revocation using locally cached CRLite data, wired into curl so an HTTPS request can spot a revoked certificate without asking a certificate authority on every connection. Several legacy interfaces go: the ENGINE interface is removed in favour of providers, SSLv3 is gone, and deprecated elliptic curves and explicit curve parameters are disabled. Teams using OpenSSL engines for HSMs, PKCS#11 tokens or TPM-backed keys have to move to the equivalent provider.

OpenSSH 10.5 ships alongside it. An empty certificate principals list in authorized_keys no longer behaves as a wildcard, sshd enforces which ECDSA algorithms it accepts, and command-line user names are validated earlier. Elsewhere, dbus-broker replaces dbus-daemon — in Ubuntu since 2004 — with AppArmor mediation preserved; ntpd-rs, a memory-safe time daemon, is available for testing, and Canonical has become a Gold Sponsor of the Trifecta Tech Foundation to fund feature parity with chrony; authd adds sign-in with a Microsoft password plus multi-factor authentication through Microsoft Authenticator, and can derive user and group IDs from identity-provider attributes so file ownership stays consistent across a fleet; and NetworkManager gains PKCS#11 and smart-card support, so YubiKeys and similar tokens can sign in to VPNs from the standard desktop.

The kernel is Linux 7.3, with updates to Landlock, AppArmor, SELinux and Smack, TPM driver work, BPF verifier fixes that close pointer leaks on speculative execution paths, NTFS3 hardening, and Rust support extended to PowerPC. Myna, Ubuntu's new desktop dictation feature, runs speech recognition locally in a sandboxed inference snap; audio is processed in memory, discarded after use, and never uploaded to a transcription service. Ubuntu 26.10 is supported until July 2027.

Our opinion

The interesting thing about Ubuntu 26.10 is how much of it is subtraction. Cutting filesystem parsers out of signed GRUB, deleting the ENGINE interface, retiring dbus-daemon and swapping GNU coreutils for a Rust implementation are all the same move — shrink the privileged surface and make the attacker's job harder than the patcher's. It is a strategy rather than a slogan, and the ordering gives it away: Canonical landed the Secure Boot changes right after a long-term support release precisely because they will break setups, and it is telling administrators to keep a supported escape hatch open until 2041.

That honesty is also the weakness. The TPM change asks users without a hardware root of trust to accept a PIN in exchange for encryption, and removing the ENGINE interface hands a migration bill to exactly the organisations running HSMs and smart cards — the ones with the least appetite for a surprise inside an upgrade window. Canonical telling people to test first is the tell: the security posture improves, but the cost lands on whoever patches on day one. Myna, meanwhile, is the rare privacy feature that is more convincing for being boring — local inference, audio discarded, nothing uploaded — and it deserves to be the template for the AI features heading for the Linux desktop.