Canonical is about to release its interim version of Ubuntu, the Stonking Stingray, a.k.a. Ubuntu 26.10, and they are doubling down on security with the upcoming Linux 7.3 kernel series, a slimmed-down GRUB bootloader, and more.

Ubuntu 26.10 (codename Stonking Stingray) is scheduled for release next week, on October 15th, 2026, with the latest and greatest GNOME 51 “A Coruña” desktop environment, the unreleased Linux 7.3 kernel series (yes, Ubuntu 26.10 will ship with an RC (Release Candidate) kernel), OpenSSL 4.0, OpenSSH 10.5, and Rust-based core utilities.

To beef up security, Canonical implemented a signed, slimmed-down GRUB bootloader with a reduced attack surface, TPM-backed encryption support on machines that don’t have a hardware root of trust, and dbus-broker as the default message bus with AppArmor mediation intact, using an event-driven architecture with better accounting, reliability, and scalability.

On top of that, Ubuntu 26.10 will ship with ntpd-rs, a memory-safe time daemon that will be enabled by default in Ubuntu 27.04, certificate revocation with upki, authd support for MS MFA and identity-provider-based accounts, hardware-token VPN sign-in support in NetworkManager, and on-device speech recognition powered by AI.

“Ubuntu 26.10 introduces Myna, a desktop speech-to-text feature. It’s designed to bring cutting-edge accessibility, without compromising security,” said Canonical in a blog post. “Myna performs speech recognition locally through an inference snap. Once the required models are installed, dictation works without an internet connection.”

Linux kernel 7.3, which will be released later this month, will also bring numerous updates to the Landlock, AppArmor, SELinux, and Smack security modules for Ubuntu 26.10, along with TPM driver updates and BPF verifier fixes to prevent pointer leaks on speculative execution paths, NTFS3 security hardening, memory-safety fixes, and Rust support for PowerPC.

Last but not least, Canonical doubles down on firmware updates via fwupd, which now asks for a recovery key only when the running system uses TPM-backed encryption and a firmware update could affect the measurements used to unlock the disk, instead of prompting unnecessarily on systems where the update doesn’t affect the TPM-backed unlock policy.

As mentioned before, Canonical plans to release Ubuntu 26.10 (Stonking Stingray) on October 15th, but if you’re eager to try it right now on your personal computer, you can download the beta release. However, please keep in mind that it’s a pre-release version, not suitable for use in production environments.

  • TeaWithDani@lemmy.world
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    edit-2
    18 hours ago

    Is it? Or is that application just not meant for this tool? You can just deliver the application as a debian package, flatpak or appimage?

    You made it seem like all snaps take 1 minute to cold start and thats why they are bad. Stuff like Firefox, Slack, Discord, Proton stuff, boot marginally slower. Steam takes a little bit (10s for me) but steam always takes a while to boot anywhere.

    Most of these are also persistent. They can’t autoupdate unless they are closed, so that scenario wouldn’t be common.

    Snaps are also really desirable for critical things like Docker or Tailscale. I want my images to roll back if the update fails. How long server apps take to boot kinda doesn’t matter.

    Like they are not a bad tool because they don’t excel in a specific use case which happens to be yours.

    I wouldn’t want to package say the Unreal Engine as a snap, because 1. its huge and would take forever to open and 2. I never want it to update. It would be a bad tool for that job.