Ubuntu 26.10 “Stonking Stingray,” currently available in beta ahead of its final release on October 15, will introduce a broad range of security changes across GRUB, disk encryption, core system utilities, cryptography, authentication, and the Linux kernel.
One of the biggest changes concerns the Secure Boot path. Canonical is reducing functionality in Ubuntu’s signed GRUB builds by removing components not required for common boot configurations to reduce the code exposed before the kernel starts.
The signed GRUB build will continue to support /boot on ext4, FAT, and ISO9660, along with squashfs. However, support for Btrfs, HFS+, XFS, and ZFS filesystem drivers is being removed, as are JPEG and PNG image loading and Apple partition tables.

Canonical is also tightening which storage layouts are supported under Secure Boot. Configurations with /boot on LVM or LUKS, as well as software RAID setups other than RAID1, will no longer be supported in that boot path.
TPM-backed full-disk encryption is expanding as well. In Ubuntu 26.10, the feature will work on machines without a hardware root of trust. Since Ubuntu cannot verify firmware integrity on those systems automatically, installation will require users to configure a PIN or passphrase.
Machines with a hardware root of trust, which Canonical says includes most PCs manufactured since 2021, will continue to support automatic unlocking.
Another major change is the completion of Ubuntu’s transition to Rust-based core utilities. Ubuntu 26.04 LTS switched to uutils coreutils by default but kept the GNU versions of cp, mv, and rm for compatibility. Ubuntu 26.10 will migrate those commands too, making the default core utilities entirely Rust-based.
Canonical advises users and administrators to test scripts that depend on subtle command behavior, especially workflows involving copying, moving, or deleting files.
The cryptography stack is also receiving a substantial update with OpenSSL 4.0, which adds Encrypted Client Hello support and introduces additional cryptographic capabilities. At the same time, several older technologies are being retired, including the ENGINE interface and SSLv3 support, while deprecated elliptic curves and explicit EC parameters are being further restricted.
Ubuntu 26.10 will also introduce upki, a system-level certificate revocation mechanism based on locally cached CRLite data. OpenSSH will move to version 10.5, with hybrid post-quantum key exchange remaining the default.
Another long-standing component is being replaced. Ubuntu 26.10 will switch from dbus-daemon, used by Ubuntu since 2004, to dbus-broker for both the system bus and user session buses.
The new implementation uses an event-driven architecture to improve accounting, reliability, and scalability. Importantly, Ubuntu’s existing AppArmor mediation for D-Bus communication will remain in place.
Moreover, the 26.10 release will include an updated ntpd-rs, a Rust-based NTP implementation, in the archive for testing. The plan is to make it Ubuntu’s default time synchronization daemon in 27.04.
Ubuntu’s authd service will gain support for Microsoft password authentication and multi-factor authentication through Microsoft Authenticator. It will also be able to derive user and group IDs directly from identity-provider attributes, allowing consistent IDs across multiple machines.
NetworkManager, meanwhile, will gain PKCS#11 and smart-card authentication support for VPN connections, including hardware security tokens such as YubiKeys.
Ubuntu 26.10 will also introduce Myna, a desktop speech-to-text feature designed to perform speech recognition locally. After installing the required models, dictation will work without an internet connection. Audio will be processed in memory and discarded after use instead of being uploaded to an external transcription service.
Finally, Ubuntu 26.10 will ship with Linux kernel 7.3. Canonical highlights security-related work across Landlock, AppArmor, SELinux, and Smack, along with TPM driver updates, BPF verifier fixes, NTFS3 hardening, and a range of memory-safety fixes across networking, filesystems, and virtualization.
For additional details, see Canonical’s announcement.
