Canonical is about to release its interim version of Ubuntu, the Stonking Stingray, a.k.a. Ubuntu 26.10, and they are doubling down on security with the upcoming Linux 7.3 kernel series, a slimmed-down GRUB bootloader, and more.

Ubuntu 26.10 (codename Stonking Stingray) is scheduled for release next week, on October 15th, 2026, with the latest and greatest GNOME 51 “A Coruña” desktop environment, the unreleased Linux 7.3 kernel series (yes, Ubuntu 26.10 will ship with an RC (Release Candidate) kernel), OpenSSL 4.0, OpenSSH 10.5, and Rust-based core utilities.

To beef up security, Canonical implemented a signed, slimmed-down GRUB bootloader with a reduced attack surface, TPM-backed encryption support on machines that don’t have a hardware root of trust, and dbus-broker as the default message bus with AppArmor mediation intact, using an event-driven architecture with better accounting, reliability, and scalability.

On top of that, Ubuntu 26.10 will ship with ntpd-rs, a memory-safe time daemon that will be enabled by default in Ubuntu 27.04, certificate revocation with upki, authd support for MS MFA and identity-provider-based accounts, hardware-token VPN sign-in support in NetworkManager, and on-device speech recognition powered by AI.

“Ubuntu 26.10 introduces Myna, a desktop speech-to-text feature. It’s designed to bring cutting-edge accessibility, without compromising security,” said Canonical in a blog post. “Myna performs speech recognition locally through an inference snap. Once the required models are installed, dictation works without an internet connection.”

Linux kernel 7.3, which will be released later this month, will also bring numerous updates to the Landlock, AppArmor, SELinux, and Smack security modules for Ubuntu 26.10, along with TPM driver updates and BPF verifier fixes to prevent pointer leaks on speculative execution paths, NTFS3 security hardening, memory-safety fixes, and Rust support for PowerPC.

Last but not least, Canonical doubles down on firmware updates via fwupd, which now asks for a recovery key only when the running system uses TPM-backed encryption and a firmware update could affect the measurements used to unlock the disk, instead of prompting unnecessarily on systems where the update doesn’t affect the TPM-backed unlock policy.

As mentioned before, Canonical plans to release Ubuntu 26.10 (Stonking Stingray) on October 15th, but if you’re eager to try it right now on your personal computer, you can download the beta release. However, please keep in mind that it’s a pre-release version, not suitable for use in production environments.

  • Guiorgy@lemmy.ml
    link
    fedilink
    arrow-up
    2
    ·
    8 hours ago

    From what I’ve seen, there are 4 core issues people complain with snaps:

    1. For full functionality, snap requires Ubuntu specific kernel patches, and has a hard dependence on Systemd, whereas Flatpaks work everywhere.
    2. Most Flatpak users default to the flarhub repo, however, just like you can have other apt sources, Flatpak supports other repos. Snaps on the other hand are exclusively tied to and controlled by Canonical, which seems very unlike Unix and rubs many wrong.
    3. You can install packages as a non-root user into your home with Flatpaks, but snaps can only be managed by root, since they are system packages. This means that they are very unsuitable for atomic distros like Fedora Silverblue.
    4. Technically not the fault of snaps but the decision by Canonical, when you try to install something with apt on Ubuntu (and derived) it may instead install it through snap, which, because of sandboxing and other security measures, may result in very unexpected and hard to diagnose issues. I personally wasted a day trying to fix a broken Docker daemon, which turned out to be due to snap, when I explicitly wanted an apt! I personally have no major issues with snaps in general, but ffs let me decide whether it’s a snap or not >_<

    Bonus: Some also complain about security, that snaps have had many vulnerabilities, and that malware was distributed as snaps, but the same has been true for Flatpaks too, so I don’t think it’s fair to point that out.