Ubuntu 26.10 delivers security updates with TPM-backed encryption, OpenSSL 4.0 & Linux 7.3
by Paul

Ubuntu 26.10 delivers security updates with TPM-backed encryption, OpenSSL 4.0 & Linux 7.3

Canonical recently announced the beta release of Ubuntu 26.10 “Stonking Stingray”, featuring one of its most extensive security upgrades to date, anchored by a migration to Linux kernel 7.3 and OpenSSL 4.0, the first major version upgrade since OpenSSL 3.0. The new kernel brings hardening across Landlock, AppArmor, SELinux, and Smack security modules, alongside BPF verifier fixes designed to prevent pointer leaks during speculative execution attacks. Ubuntu 26.10 also adopts hybrid post-quantum key exchange as the default in OpenSSL's TLS configuration, making ML-KEM, ML-DSA, and SLH-DSA cryptographic standards available to users ahead of anticipated quantum computing threats.

Beyond cryptography, the release introduces memory-safety improvements throughout the system, including core utilities now written entirely in Rust (replacing remaining GNU implementations of cp, mv, and rm), and dbus-broker replacing the decade-old dbus-daemon for improved reliability and scalability. TPM-backed full disk encryption has expanded to machines without a hardware root of trust, while a streamlined signed GRUB removes unnecessary filesystem drivers like Btrfs, XFS, and ZFS from the Secure Boot path. New privacy-focused features include Myna, an on-device speech-to-text tool that processes audio locally through a sandboxed snap without cloud transmission, and upki, a certificate revocation system integrated with curl to detect revoked certificates during HTTPS verification.

Enterprises will benefit from enhanced authentication capabilities, with authd supporting Microsoft password sign-in and multi-factor authentication through Microsoft Authenticator, plus NetworkManager gaining PKCS#11 and smart-card support for hardware token VPN access. However, users should note significant migration requirements: the OpenSSL ENGINE interface has been removed in favor of providers, requiring HSM and PKCS#11 token configurations to update, while grub limitations mean /boot on LVM, software RAID beyond RAID1, and LUKS encryption are no longer supported under Secure Boot. Ubuntu recommends testing scripts against new Rust defaults and verifying hardware provider compatibility before deployment.

Paul
Written by Paul
Follow
Add as a preferred source on Google
Ubuntu iconUbuntu
  2412
  • ...

Ubuntu is a Linux-based operating system developed by a community, suitable for laptops, desktops, and servers. It includes essential applications like a web browser, office suite, and instant messaging. Based on Debian, it utilizes the APT package manager for software management. Ubuntu is rated 3.8 and stands out for its versatility and wide usage.

No comments so far, maybe you want to be first?