Canonical is about to release its interim version of Ubuntu, the Stonking Stingray, a.k.a. Ubuntu 26.10, and they are doubling down on security with the upcoming Linux 7.3 kernel series, a slimmed-down GRUB bootloader, and more.

Ubuntu 26.10 (codename Stonking Stingray) is scheduled for release next week, on October 15th, 2026, with the latest and greatest GNOME 51 “A Coruña” desktop environment, the unreleased Linux 7.3 kernel series (yes, Ubuntu 26.10 will ship with an RC (Release Candidate) kernel), OpenSSL 4.0, OpenSSH 10.5, and Rust-based core utilities.

To beef up security, Canonical implemented a signed, slimmed-down GRUB bootloader with a reduced attack surface, TPM-backed encryption support on machines that don’t have a hardware root of trust, and dbus-broker as the default message bus with AppArmor mediation intact, using an event-driven architecture with better accounting, reliability, and scalability.

On top of that, Ubuntu 26.10 will ship with ntpd-rs, a memory-safe time daemon that will be enabled by default in Ubuntu 27.04, certificate revocation with upki, authd support for MS MFA and identity-provider-based accounts, hardware-token VPN sign-in support in NetworkManager, and on-device speech recognition powered by AI.

“Ubuntu 26.10 introduces Myna, a desktop speech-to-text feature. It’s designed to bring cutting-edge accessibility, without compromising security,” said Canonical in a blog post. “Myna performs speech recognition locally through an inference snap. Once the required models are installed, dictation works without an internet connection.”

Linux kernel 7.3, which will be released later this month, will also bring numerous updates to the Landlock, AppArmor, SELinux, and Smack security modules for Ubuntu 26.10, along with TPM driver updates and BPF verifier fixes to prevent pointer leaks on speculative execution paths, NTFS3 security hardening, memory-safety fixes, and Rust support for PowerPC.

Last but not least, Canonical doubles down on firmware updates via fwupd, which now asks for a recovery key only when the running system uses TPM-backed encryption and a firmware update could affect the measurements used to unlock the disk, instead of prompting unnecessarily on systems where the update doesn’t affect the TPM-backed unlock policy.

As mentioned before, Canonical plans to release Ubuntu 26.10 (Stonking Stingray) on October 15th, but if you’re eager to try it right now on your personal computer, you can download the beta release. However, please keep in mind that it’s a pre-release version, not suitable for use in production environments.

  • [object Object]@lemmy.ca
    link
    fedilink
    arrow-up
    6
    arrow-down
    1
    ·
    9 hours ago

    I really like some of the direction Canonical is going, but very much do not like how they’re getting there.

    Rust core utils sounds great, this sounds great, but practically I feel both need a lot of time in the oven to come out right and that’s okay.

    I also i feel like snaps have lost and can be considered a mistake. I don’t use snaps, so I can’t explain why, but everyone is saying it.

    • trevor (any/all) @lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 hours ago

      Most people hate Snaps because the Snapstore backend is proprietary (which is a valid reason to hate them).

      I despise Snaps because their cold start times are dreadful (yes, even with LZMA compression, which Canonical wants you to believe solved this). When a Snap launches after first installation or after an update, you’re looking at anywhere from 15-60 seconds of unresponsiveness while your system appears to fail to launch the application, even though it’s actually because the shitty Snap needs to decompress the disk images and pollute your loopback devices.

      Combine the terrible cold start times with the fact that the default behavior of Snaps is to phone home to the Snapstore whenever they want to check for updates and you’re going to create bad experiences for people (especially newbies) that think “Linux is garbage” because Canonical decided this was a great idea to force on people.

      They also keep Snapifying core parts of Ubuntu like the kernel itself and GNOME, making them impossible to avoid if you want or need to use Ubuntu.

    • neon_nova@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 hours ago

      I feel the same way about snaps. It’s the main reason why I do not use Ubuntu. If they didn’t make snaps mandatory, I would use Ubuntu instead of mine or Fedora