---
title: What’s new in security for Ubuntu 26.10?
description: Discover what’s new in Ubuntu 26.10 security, including Rust core utilities,
  a smaller Secure Boot path, TPM-backed encryption, OpenSSL 4.0, and more.
url: https://canonical.com/blog/ubuntu-26-10-security
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi "More about Ijlal Loutfi")

6 October 2026

# What’s new in security for Ubuntu 26.10?

[Security](https://canonical.com/blog/tag/security)
[Ubuntu](https://canonical.com/blog/tag/ubuntu)

---

Share the article

Ubuntu 26.10 “Stonking Stingray” arrives at a time when AI tools are accelerating vulnerability discovery. Patching faster is essential, but the resilience of the underlying operating system must also limit what an attacker can achieve before a fix is available.

To respond to this new threat landscape, Ubuntu 26.10 continues the work of previous releases by reducing the code exposed to attack: replacing memory-unsafe implementations while preserving confinement as components change. Security doesn’t just relate to security features; it informs the approach we take wherever we innovate. Let’s take [Myna](https://discourse.ubuntu.com/t/introducing-myna-speech-to-text-for-ubuntu-desktop/84251), Ubuntu’s new desktop dictation feature. Its speech recognition runs locally through a sandboxed inference snap, so audio does not need to be sent to a cloud service for transcription.

In this blog, we’ll look through what’s changed in security for Ubuntu 26.10, the protection each change provides, and what you need to check before upgrading. Here’s a quick rundown if you want to find something specific:

* A signed, slimmed down GRUB with a reduced attack surface
* TPM-backed encryption on machines without a hardware root of trust
* Core utilities that are now entirely in Rust
* OpenSSL 4.0, OpenSSH 10.5 and certificate revocation with upki
* dbus-broker as the default message bus, with AppArmor mediation intact
* ntpd-rs, a memory-safe time daemon, available for testing
* authd support for Microsoft MFA and identity-provider-based accounts, plus hardware-token VPN sign-in in NetworkManager
* On-device speech recognition
* Linux 7.3

# A smaller Secure Boot path

GRUB is part of Ubuntu’s early boot chain. In the usual UEFI Secure Boot configuration, the firmware first loads [shim](https://documentation.ubuntu.com/security/security-features/platform-protections/secure-boot), which then validates and loads GRUB. It contains parsers for filesystems, image formats, and partition layouts that, over the years, have been a steady source of Secure Boot bypass vulnerabilities.

In Ubuntu 26.10, signed GRUB builds retain only what Ubuntu *needs* to boot:

* /boot on ext4, FAT, and ISO9660 remains supported, along with squashfs for snaps.
* Filesystem drivers for Btrfs, HFS+, XFS, and ZFS have been removed from the signed build, as have JPEG and PNG image loading and Apple partition tables.
* /boot on LVM, software RAID other than RAID1, and LUKS encryption are no longer supported under Secure Boot.

This reduces the potential attack surface during the boot sequence. These changes affect only the boot path, with LVM, RAID, LUKS, Btrfs, and ZFS continuing to work in the running system. The full feature set also remains available with Secure Boot disabled. Check any customized /boot layout against the supported list before upgrading.

Fewer parsers running before the kernel means fewer ways to break the chain of trust. We deliberately made this change directly after a long-term supported release (in this case, Ubuntu 26.04 LTS), so that anyone who depends on the removed features can stay on Ubuntu 26.04 LTS until May 2041 with Ubuntu Pro and the Legacy add-on.

Encrypting /boot alone does not authenticate its contents or establish a trusted boot chain. Ubuntu’s TPM-backed full disk encryption combines boot-chain protections with measured boot and a policy governing when the disk-unlocking key can be released. Let’s dive into that now.

# TPM-backed encryption on more machines

TPM-backed full disk encryption protects data at rest and ties automatic disk unlocking to the system’s measured boot state. The TPM releases the disk-unlocking key only when those measurements satisfy the configured security policy. In Ubuntu 26.10, TPM-backed full disk encryption reaches systems without a hardware root of trust. Ubuntu cannot verify the firmware automatically on these machines, so they require a PIN or passphrase at installation.

Administrators can remove the PIN later. However, without it, the system is no longer protected against firmware tampering. Machines with a hardware root of trust, which covers most PCs made since 2021, continue to unlock automatically.

The firmware update flow has also changed. fwupd now asks for a recovery key only when the running system uses TPM-backed encryption and a firmware update could affect the measurements used to unlock the disk, rather than prompting unnecessarily on systems where the update does not affect the TPM-backed unlock policy. This fix has also been backported to Ubuntu 26.04 LTS.

# Core utilities, now entirely Rust

Ubuntu 26.04 LTS made the Rust-based uutils coreutils the default, but it retained the GNU implementations of cp, mv, and rm for compatibility. Ubuntu 26.10 migrates those remaining tools. The default core utilities now run entirely on Rust.

These are commands that scripts, packages, and administrators use all day, every day. *Safe Rust* prevents classes of memory-safety errors, including use-after-free and out-of-bounds memory access through compile-time checks and runtime checks where necessary. This reduces the scope for memory-corruption vulnerabilities, although it does not prevent logic errors or vulnerabilities in unsafe code and dependencies.

We encourage everyone to test their scripts that depend on subtle command behaviour against the new defaults, particularly privileged workflows that copy, move, or delete files.

# OpenSSL 4.0 and OpenSSH 10.5

A sufficiently powerful quantum computer could break widely deployed public-key algorithms, such as RSA and elliptic-curve cryptography, which we use today to secure connections and verify signatures. Post-quantum algorithms are designed to withstand that threat. Ubuntu is adding them because data encrypted today could be collected and decrypted in the future.

Ubuntu 26.10 moves to OpenSSL 4.0 (OpenSSL is the global standard for internet encryption), the first new major version since OpenSSL 3.0. This builds on the post-quantum foundations of Ubuntu 26.04 LTS. Like Ubuntu 26.04 LTS, Ubuntu 26.10 makes ML-KEM, ML-DSA, and SLH-DSA available to users, with hybrid post-quantum key exchange being preferred by default in OpenSSL’s TLS configuration when supported by the peer. OpenSSL 4.0 adds the curveSM2MLKEM768 hybrid key-exchange group, the ML-DSA-MU pseudo-digest, and the cSHAKE function.

It also introduces support for Encrypted Client Hello (ECH). When enabled by compatible applications and servers, ECH protects the inner TLS ClientHello, including the requested server name. It does not hide the destination IP address or prevent all traffic analysis, and installing OpenSSL 4.0 does not automatically enable ECH for every application.

Ubuntu 26.10 also introduces upki, a system-level approach to certificate revocation. Linux command-line tools have historically lacked the browser-grade revocation infrastructure used by browsers such as Firefox and Chromium, which means an application can successfully validate a certificate chain without necessarily knowing that a certificate has since been revoked.

upki uses locally cached CRLite revocation data so applications can check certificate revocation without making a separate online request to a certificate authority for every connection. In Ubuntu 26.10, this is integrated with curl, allowing HTTPS connections made through curl to detect revoked certificates as part of certificate verification. The revocation data is updated periodically in the background.

Several legacy interfaces and algorithms have been removed or restricted:

* The ENGINE interface has been removed in favor of providers.
* SSLv3 support has been removed.
* Support for deprecated elliptic curves in TLS and for explicit elliptic-curve parameters is disabled.
* Certificate and revocation checks have been tightened, including additional authority-key-identifier checks when strict X.509 verification is enabled.

If you rely on OpenSSL engines for HSMs, PKCS#11 tokens, or TPM-backed keys, now is the time to switch to the equivalent provider: OpenSSL’s newer plug-in interface. Check that a suitable provider exists for your hardware and workflows, and test the migration. These changes reduce legacy code and extend cryptographic capabilities, but they can require application and configuration changes.

Ubuntu 26.10 also ships OpenSSH 10.5. Hybrid post-quantum key exchange remains the default. This includes fixes introduced in OpenSSH 10.3 for certificate and command-line handling:

* When checking certificates through the authorized\_keys principals= option, an empty certificate principals list no longer acts as a wildcard.
* sshd correctly enforces restrictions on which ECDSA algorithms it accepts.
* Validation of command-line user names happens earlier, addressing cases where shell metacharacters could otherwise be expanded through configuration tokens in ssh\_config.

# dbus-broker replaces dbus-daemon

D-Bus lets applications and services communicate, whether they are connecting to Wi-Fi or mounting a USB drive. It is a trust boundary because unprivileged processes use it to reach privileged ones. Ubuntu uses AppArmor to control which D-Bus interfaces snaps and critical packages can access.

Ubuntu 26.10 replaces dbus-daemon, used in Ubuntu since 2004, with dbus-broker. The replacement uses an event-driven architecture with better accounting, reliability, and scalability. Both the system bus and every user session bus will change on fresh installations and upgrades.

The switch to dbus-broker preserves AppArmor’s control over which D-Bus messages applications can send and receive. This keeps existing confinement policies enforced as Ubuntu replaces the message bus implementation. Ubuntu 26.10 also includes further fixes to this AppArmor integration.

# Memory-safe time synchronization, ready for testing

Accurate time underpins TLS certificate validation, Kerberos, reliable log timestamps, and audit trails. If a system clock is significantly wrong, valid certificates can appear expired or not yet valid, Kerberos authentication can fail because of clock skew, and security logs can become difficult to correlate reliably across systems. Ubuntu 26.10 includes an updated version of ntpd-rs, a memory-safe NTP implementation, in the archive for testing, and the goal is to make it the default in Ubuntu 27.04.

To accelerate this transition, Canonical has become a Gold Sponsor of the Trifecta Tech Foundation and is funding aspects of ntpd-rs development. The funding supports feature parity with chrony, including multi-threaded NTP servers and GPSd support, as well as AppArmor and seccomp confinement.

Time daemons run for long periods and face the network. Memory-safe code reduces the risk of memory-corruption vulnerabilities, while confinement limits the damage a compromised daemon can cause. Both matter as Ubuntu prepares for the transition.

# Enterprise authentication from sign-in to VPN

Ubuntu’s authd service lets users sign into their Ubuntu machines with an account managed by a cloud identity provider using OpenID Connect. In Ubuntu 26.10, authd adds support for signing in with a Microsoft password and completing multi-factor authentication through Microsoft Authenticator.

Separately, authd now derives user and group IDs directly from identity-provider attributes, keeping those IDs consistent across machines in a fleet. This helps ensure that shared files retain the correct ownership and permissions. Administrators can also disable local password authentication for these accounts, requiring users to authenticate through their identity provider.

For VPN access, NetworkManager gains PKCS#11 and smart-card support. Users can authenticate with hardware tokens, such as YubiKeys, through the standard desktop interface. These changes help organizations extend their existing identity, MFA, and hardware-token policies to Ubuntu sign-in and VPN access, without exceptions to explain to auditors.

# On-device speech recognition

Ubuntu 26.10 introduces [Myna](https://discourse.ubuntu.com/t/introducing-myna-speech-to-text-for-ubuntu-desktop/84251), a desktop speech-to-text feature. It’s designed to bring cutting-edge accessibility, without compromising security.

[Myna](https://discourse.ubuntu.com/t/introducing-myna-speech-to-text-for-ubuntu-desktop/84251) performs speech recognition locally through an inference snap. Once the required models are installed, dictation works without an internet connection. Audio is processed in memory, discarded after use, and is not uploaded to an external transcription service.

This privacy protection applies to speech recognition. The resulting text is inserted into the application you are using, whose own storage and network behaviour still applies.

Where AI sends data is a critical security question, and Myna addresses this through local inference and confinement of its snap components, without requiring cloud-based transcription.

# Linux kernel 7.3

Ubuntu 26.10 ships with Linux kernel 7.3, following Ubuntu’s policy of shipping the latest upstream kernel available at release freeze. As a result, users receive the newest upstream hardening and hardware security enablement as early as possible.

This cycle’s security work includes updates to the Landlock, AppArmor, SELinux, and Smack security modules. There are also TPM driver updates and BPF verifier fixes that prevent pointer leaks on speculative execution paths. NTFS3 received security hardening, and Rust support in the kernel now extends to PowerPC. The release candidates also carried a large batch of memory-safety fixes, many of them found by fuzzing, for use-after-free and overflow bugs across networking, filesystems, and virtualization.

# Towards 28.04 LTS

Interim releases give us room to make substantial changes ahead of an LTS, so that the next long-term release can benefit from both security and stability improvements. Ubuntu 26.10 sets the  direction for Ubuntu 28.04 LTS with less code in privileged components, from GRUB to OpenSSL, and more memory safety across the system. Hardware-backed encryption comes with explicitly documented trade-offs. Enterprise identity policies extend from sign-in to VPN, while Myna keeps speech recognition local.

Ubuntu 26.10 is supported until July 2027. [Test it against your workloads](https://discourse.ubuntu.com/t/ubuntu-desktop-26-10-stonking-stingray-roadmap-building-toward-ubuntu-28-04-lts/83751), and tell us what you find. Your feedback shapes Ubuntu 28.04 LTS.

# Further reading

* [Streamlining Secure Boot for 26.10](https://discourse.ubuntu.com/t/streamlining-secure-boot-for-26-10/79069?utm_source=chatgpt.com)
* [Ubuntu 26.10 is switching to dbus-broker](https://discourse.ubuntu.com/t/ubuntu-26-10-is-switching-to-dbus-broker/84060?utm_source=chatgpt.com)
* [Ntpd-rs: it’s about time!](https://discourse.ubuntu.com/t/ntpd-rs-its-about-time/79154?utm_source=chatgpt.com)
* [Microsoft Entra ID Password and MFA sign-in comes to Ubuntu](https://discourse.ubuntu.com/t/microsoft-entra-id-password-and-mfa-sign-in-comes-to-ubuntu/88342?utm_source=chatgpt.com)
* [Introducing Myna: Speech to Text for Ubuntu Desktop](https://discourse.ubuntu.com/t/introducing-myna-speech-to-text-for-ubuntu-desktop/84251?utm_source=chatgpt.com)
* [An update on rust-coreutils](https://discourse.ubuntu.com/t/an-update-on-rust-coreutils/80773?utm_source=chatgpt.com)
* [Post Quantum Support in the upcoming 26.04 LTS](https://discourse.ubuntu.com/t/post-quantum-support-in-the-upcoming-26-04-lts/76840?utm_source=chatgpt.com)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

In submitting this form, I confirm that I have read and agree to
[Canonical's Privacy Notice](https://canonical.com/legal/data-privacy/contact)
and [Privacy Policy](https://canonical.com/legal/data-privacy).

Sign up

## Share on

---

## Related posts

[### Confidential computing in the real world: finding your use case](https://canonical.com/blog/confidential-computing-use-cases)

Confidential computing is essential when an organization needs to process sensitive data on infrastructure where the operators should not have access to it. You might have seen...

[Ijlal Loutfi](https://canonical.com/blog/author/ijlal-loutfi)

2 October 2026

[### Canonical announces the alpha release of Charmed OpenShell to help secure autonomous AI agent fleets](https://canonical.com/blog/charmed-openshell-alpha-release)

To streamline enterprise deployment and lifecycle management, Canonical is announcing the alpha release of Charmed OpenShell.

[Canonical](https://canonical.com/blog/author/canonical)

28 September 2026

[### Ubuntu coming soon to Snapdragon X2 Series platforms, unlocking more Linux PCs for the agentic world](https://canonical.com/blog/ubuntu-coming-soon-to-qualcomm-snapdragon-x2-series-platforms)

Canonical and Qualcomm Technologies announce upcoming native Ubuntu support for Qualcomm’s flagship laptop silicon, delivering multi-day battery life, 80 TOPS NPU acceleration,...

[Canonical](https://canonical.com/blog/author/canonical)

23 September 2026

[### Accelerating delivery of CVE fixes with a new Kernel release strategy](https://canonical.com/blog/accelerating-delivery-of-cve-fixes-with-a-new-kernel-release-strategy)

When it comes to fixing security vulnerabilities, speed is crucial. Canonical is officially outlining a transition from its current 4-week regular and 2-week security kernel...

[Canonical](https://canonical.com/blog/author/canonical)

23 September 2026
