Ubuntu

Operating SystemsLinux

The Linux distribution with a new release every six months and an LTS every two years.

Latest 26.04 · · Linuxby CanonicalWebsite

Release activity

Release activity — 2 releases across 2 days in the last year. Each cell is one day; darker means more releases that day. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026
MondayNo releases on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026
TuesdayNo releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026
WednesdayNo releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026

2 releases in the last year

Changelog

26.04

LTS

Ubuntu 26.04 LTS release notes

23 April 2026 These release notes cover new features and changes in Ubuntu 26.04 LTS (Resolute Raccoon).

Changes since your version of Ubuntu

The majority of Ubuntu users upgrade every two years, following LTS releases. Other users prefer the more frequent interim releases that come out every six months. Find the news relevant to your system: For Ubuntu LTS users If you’re upgrading from Ubuntu 24.04 LTS (Noble Numbat), read an overview of the major changes between the two LTS releases. Ubuntu 26.04 LTS summary For Ubuntu interim users If you’re upgrading from Ubuntu 25.10 (Questing Quokka), read a detailed list of changes since the previous interim release. Ubuntu 26.04 LTS changes since 25.10 Upgrading from older releases If you’re currently using an older Ubuntu LTS or interim release, such as Ubuntu 22.04 LTS or 25.04, you must first upgrade to either Ubuntu 24.04 LTS or 25.10 before you can proceed to 26.04 LTS.

Support lifespan

Ubuntu 26.04 LTS is designated as a long-term support release. This means it will continue to receive security updates and critical bug fixes for five years. Ubuntu 26.04 LTS will be supported until April 2031. With an Ubuntu Pro subscription, access to ESM (Expanded Security Maintenance) updates will be available for ten years. See our Release policy and schedule.

Requirements and compatibility

Ubuntu Desktop 26.04 LTS requires a 2 GHz dual-core processor or better, a minimum of 6 GB RAM and 25 GB of free storage space for a comfortable experience. Although it’s possible to install Ubuntu Desktop on systems with lower specifications, we recommend using an Ubuntu flavor instead in that case. For example, you can install Xubuntu or Lubuntu on systems with 2 GB RAM or more. Requirements for Ubuntu Server 26.04 LTS scale with your specific use case, starting as low as 1.5 GB RAM and 4 GB of storage space. For ISO-based installs, you will need a USB port or DVD drive for the installation media. Alternatively, Ubuntu Server is also available as pre-built images for cloud, virtualized, and bare-metal environments, which utilize their own deployment mechanisms. While an internet connection is recommended for updates and additional software, it is not required for the initial installation.

Official flavors

Find the release notes for the official flavors at the following links:

  • Edubuntu Release Notes
  • Kubuntu Release Notes
  • Lubuntu Release Notes
  • Ubuntu Budgie Release Notes
  • Ubuntu Studio Release Notes
  • Xubuntu Release Notes
  • Ubuntu Unity Release Notes
  • Ubuntu Kylin Release Notes
  • Ubuntu Cinnamon Release Notes
View originalPermalink
How 26.04 went

25.10

Added 5
  • linux-generic for arm64 now provides broader compatibility for arm64 desktop platforms using UEFI for booting
  • Ubuntu 6.17 kernel ships with early support for kexec/kdump for TDX-enabled hosts
  • .NET 10 now available
  • Zig is available for the first time in Ubuntu, defaults to version 0.14.1
  • New TPM-backed disk encryption features including passphrase support, recovery key regeneration, and firmware update integration
Changed 13
  • Linux kernel updated to version 6.17
  • Ubuntu RISC-V kernel (linux-riscv) will only support hardware that implements the RVA23S64 ISA profile
  • systemd updated to version 257.9
  • sudo-rs is now the default sudo provider, version 0.2.8 with support for older Linux kernels, sudoedit, NOEXEC and AppArmor profile switching
  • sudo (original) upgraded to version 1.9.17p2 with binary files renamed with .ws suffix
  • Core utilities now provided by rust-coreutils package version 0.2.2 with performance improvements
Removed 1
  • sudo-ldap package has been removed
Deprecated 1
  • linux-modules-extra-* packages have been deprecated in favor of linux-modules-<version>-<flavor> packages

Ubuntu 25.10 release notes

These release notes for Ubuntu 25.10 (Questing Quokka) provide an overview of the release and document the known issues with Ubuntu and its flavors.

Support lifespan

Ubuntu 25.10 will be supported for 9 months until July 2026. If you need long term support, we recommend you use Ubuntu 24.04.3 LTS which is supported until at least 2029.

Upgrades

Upgrades to 25.10 are expected to be enabled on or before Nov 3. Current blockers:

  • LP#2125535
  • LP#2127970
New features in 25.10
Updated Packages
Linux kernel 6.17🐧

This release delivers the newest 6.17 Linux kernel. Due to the final upstream release occurring after Kernel Freeze, the kernels shipped with the release images will be based on 6.17-rc7. Updates for all Questing Quokka kernels are scheduled for release in the subsequent week to incorporate the final upstream 6.17 release. Highlights for this release:

  • The linux-modules-extra-* packages have been deprecated (LP#2042831). All the kernel modules are now shipped by the linux-modules-- packages.
  • linux-generic for arm64 will provide via stubble broader compatibility for arm64 desktop platforms that utilize UEFI for booting (LP#2121352).
  • The foundation for Intel TDX Host Support was merged upstream on Linux 6.16 with additional improvements included in 6.17. The Ubuntu 6.17 kernel will ship with early support for kexec/kdump for TDX-enabled hosts (LP#2121873).
  • From 25.10, the Ubuntu RISC-V kernel (linux-riscv) will only support hardware that implements the RVA23S64 ISA profile. Systems that don’t satisfy this requirement will not be able to run 25.10. The RISC-V kernel in 24.04 will continue to support boards with RVA20 processor cores.
  • Other features can be found in the Linux 6.17 upstream changelog.
systemd v257.9

The init system was updated to systemd v257.9. See the upstream changelog for more information about individual features.

sudo-rs and sudo

sudo-rs is the default sudo provider on Ubuntu from 25.10 onwards. 0.2.8 release includes support for older Linux kernels < 5.9, sudoedit, support for NOEXEC and AppArmor profile switching. The Ubuntu release also includes various bug fixes picked from the main upstream branch. sudo (original sudo maintained by Todd C. Miller) has been upgraded to the latest version 1.9.17p2. The binary files are now renamed with the .ws suffix. Additionally, sudo-ldap package has been removed, please switch to using LDAP authentication via PAM. Please see Ubuntu Server Docs for configuring default sudo provider and differences between sudo-rs and sudo.ws.

rust-coreutils and gnu-coreutils

The core utilities of the operating system are now provided by the rust-coreutils package. We just updated to the latest version of it: 0.2.2, which features incredible performance improvements to base64 amongst other things. As rust-coreutils are not necessarily fully compatible yet, we are providing the old utilities by the side, so you can switch back and forth between them. We are also keeping a list of these diversions here.

Netplan v1.1.2ubuntu3 🌐

Adds support non-standard OVS setups, e.g. inside snap environments.

Toolchain Upgrades 🛠️
  • GCC 🐄 GCC is updated to 15.2, binutils to 2.45, and glibc to 2.42
  • Python 🐍 is updated to 3.13.7 while 3.14 is now available
  • LLVM 🐉 defaults to version 20 while 21 is now available
  • Rust 🦀 toolchain defaults to version 1.85 while 1.88 is now available
  • Golang 🐀 is updated to 1.24
  • OpenJDK ☕ defaults to 21 (LTS), while version 25 (LTS) and an early access snapshot of version 26 are now available
  • .NET 10 🦄 now available
  • Zig ⚡ is available for the first time in Ubuntu, defaults to version 0.14.1.
  • And Ubuntu Toolchains has a new homepage
OpenJDK

OpenJDK 21 is still the default. OpenJDK 25 (LTS) is now available. An early access snapshot of OpenJDK 26 is also included. Support for OpenJDK LTS versions 17, 11 and 8 is being maintained. OpenJDK with CRaC version 25 is also made available, while versions 17 and 21 continue to be supported. The devpack-for-spring snap now supports development environment setup, by automating the installation and configuration of development tools (OpenJDK, container runtime, IDEs etc.) selected by the user. The Maven and Gradle plugins for Rockcraft have been extended to support native images compiled by GraalVM. GraalVM Community Edition v25 is available through the graalvm-jdk snap, while GraalVM CE v21 continues to be supported. The snap is now available on arm64 too.

.NET

.NET versions 8 and 9 continue to be supported. The .NET 10 RC1 SDK and runtimes are now included. Following its general availability in November, the final release will be provided as a subsequent package update. Alternatively, .NET 10 is available on the latest/beta channel of the official .NET snap. It will be promoted to the latest/stable channel upon final release in November. Support for the PowerShell snap has been expanded to include the arm64, s390x, and ppc64el architectures, broadening its availability across platforms.

Default configuration changes ⚙️
Ubuntu Desktop
Installer

New TPM-Backed disk encryption features include:

  • Passphrase support and management
  • Regeneration of the recovery key
  • Better integration with firmware updates When you enable Install third-party software for graphics and Wi-Fi hardware and additional media formats during installation, screen recording will be hardware accelerated for supported hardware. The installer has also seen plenty of accessibility fixes.
Updates

When system updates are available, the Software Updater window no longer pops up unprompted, stealing the keyboard focus. Instead, a notification shows up with options to open the Software Updater or to install all updates directly. An icon in the system tray reminds you that updates are available even after dismissing the notification. It also provides a quick way to apply all the updates or inspect them in the Software Updater.

Enterprise

authd: Ubuntu’s cloud authentication solution:

  • Supports device registration with EntraID
  • authctl is a new command line tool to manage authd
  • Many improvements and important bug fixes such as UID/GID handling
Wayland
  • The Ubuntu Desktop session now runs only on the Wayland back end. The Ubuntu on X.org session is no longer available because GNOME Shell can no longer run as an X.org session.
  • Suspend-resume support is now enabled in the proprietary Nvidia driver so as to prevent corruption and freezes when waking an Nvidia desktop.
GNOME 👣
  • GNOME Shell and related components have been updated to GNOME 49.
  • You can now set an application to start automatically after login in Settings -> Apps.
  • Fractional scaling factors are now optimized so as to minimize blur.
  • The default monospace font size has been reduced to match the default user interface font size. The monospace font is used in terminals and similar applications.
New default applications
  • The Image Viewer app is now provided by Loupe instead of Eye of GNOME (EOG). Loupe is written in Rust and powered by the Glycin library.
  • The Terminal app is now provided by Ptyxis instead of GNOME Terminal.
Security Center
  • You can now manage your recovery key for the TPM-backed Full Disk Encryption. For details, see Encrypt your disk with TPM.
Ubuntu Insights

Ubuntu Insights is being developed as a replacement for Ubuntu Report and gives you more control over the non-personally identifying system metrics that you choose to share with Canonical. The metrics collection is opt-in. In this release, Ubuntu Insights introduces periodic metric collection and replaces Ubuntu Report integration in GNOME Initial Setup. Note: Any consent that you previously granted to Ubuntu Report will not be carried over to Ubuntu Insights.

Dracut

Ubuntu Desktop 25.10 now uses Dracut as its default initial ramdisk infrastructure, replacing initramfs-tools. Dracut uses systemd in the initial ramdisk and supports new features like Bluetooth and NVM Express over Fabrics (NVMe-oF). Ubuntu Server installations and Ubuntu Desktop for Raspberry Pi continue to use initramfs-tools while we port the remaining hooks. The original initramfs-tools remains supported and you can switch between the two implementations if required. For details about the switch, see https://discourse.ubuntu.com/t/spec-switch-to-dracut/54776.

Updated Applications
  • Firefox 143 🔥🦊
  • LibreOffice 25.8 📚
  • OpenVINO™ Toolkit 2025.2.0 🤖 includes openvino.genai for the first time. Also related to that:
  • Audacity 3.7.1 🎧 comes with OpenVINO™ AI plugins for music separation, noise suppression, music generation and continuation, transcription, and super resolution, and can be run on Intel CPU, GPU, and NPU.
  • GIMP 3.0.4 🖼️ which supports the usage of the snap to add AI functionality to GIMP for stable diffusion, super resolution, and semantic segmentation via OpenVINO™ AI plugins for GIMP 3.1.2.
Updated Subsystems
  • BlueZ 5.83 💙
  • Pipewire 1.4.7 🔊
Support for new Intel® integrated and discrete GPUS

This release brings full support for Intel® Core™ Ultra Xe3 integrated Intel® Arc™ graphics, and Intel® Arc™ Pro B50 and B60 “Battlemage” discrete GPUs. Further Intel® Graphics related features are now available by changes in various components:

  • Via the Linux Kernel v6.17:
  • Initial support for Intel’s next-gen client platform codenamed Panther Lake
  • Enhanced IOMMU and PCIe subsystem for improved GPU virtualization and passthrough.
  • Improved multi-GPU configuration support for Intel hardware.
  • Via Mesa 25.2.3:
  • VK_KHR_shader_bfloat16 enabled in Intel ANV Vulkan driver for Battlemage and Panther Lake** (GFX125+).
  • Completed OpenCL 2.0 coarse grain buffer SVM support in Iris driver.
  • Improved color fast-clear handling and multi-engine surface usage for Intel Vulkan (ANV) driver.
  • Via intel-media-driver 25.3.0:
  • Panther Lake Upstream decoding and VP9 encoding support
  • Via intel-compute-runtime 25.31:
  • Enabling a Level Zero device unified shared memory (USM) pool as a performance change.
  • A performance-minded change for Xe2 graphics to ensure Level Zero events are always allocated in the local device memory.
  • Via level-zero 1.24
  • Update Level Zero Loader and Headers to support v1.13.1 of L0 Spec
  • Via level-zero-raytracing 1.1.0:
  • Ray Tracing Acceleration Structure (RTAS) Extensions
Ubuntu Foundations
Cryptography
Libraries

OpenSSL has been updated to 3.5.3 (It includes security patches from 3.5.4). The most notable updates are:

  • Support for server side QUIC (RFC 9000).
  • Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA).
  • The default TLS supported groups list has been changed to include and prefer Hybrid PQC KEM groups.
Package Management: APT 3.1

APT has been updated to 3.1.6, the latest release, including many new features:

  • The new solver is now the default. For more insight, see the post “How we delivered the new APT solver in 25.10”
  • The apt why and apt why-not commands have been added that tell you why the solver installed or could not install a package.
  • Repositories can now be configured with Include and Exclude directives. In the Include case, only these packages are included; in the Exclude case, these packages are excluded from the repository. This allows you to restrict a repository to specific packages.
  • The apt history-list and apt history-info commands are included as an early preview easter egg. Enjoy!
Ubuntu Server
ubuntu-server Meta and Seed

Starting in 25.10, the default Ubuntu server image and ubuntu-server metapackage have been updated. Read more at the public spec on Discourse. …

View originalPermalink
How 25.10 went

25.04

Added 15
  • Linux kernel 6.14 with sched_ext scheduling system enabling eBPF-based scheduling policies
  • NTSYNC driver emulating WinNT sync primitives for improved Windows games performance on Wine and Proton
  • bpftools and linux-perf tools decoupled from kernel version and shipped in separate packages
  • Netplan v1.1.2 support for wpa-psk-sha256 WiFis
  • Netplan v1.1.2 support for routing-policy configuration on NetworkManager backend
  • systemd-networkd-wait-online functionality to wait for DNS servers to be configured and reachable
Changed 4
  • systemd updated to v257.4
  • systemd no longer built with utmp support
  • linux-lowlatency binary package retired in favour of linux-generic with lowlatency-kernel userspace package
  • powershell-preview snap updated to build from source
Deprecated 2
  • System V service scripts support deprecated and scheduled for removal in systemd v258
  • cgroup v1 support scheduled for complete removal in systemd v258

Ubuntu 25.04 release notes

These release notes for Ubuntu 25.04 (Plucky Puffin) provide an overview of the release and document the known issues with Ubuntu and its flavors.

Dedication

Subscribers to the ubuntu-{devel-}announce mailing list and long term participants in the Ubuntu community will have come across Steve Langasek’s work. Steve, known in the community as vorlon, was a long-term member of the Release team (along with being a member of Archive Admin, Techboard, SRU team, and so on) and a colleague to many of us at Canonical. As a member of the Release team, Steve was responsible for devising many of the processes, policies, and tools which we use today, and teaching his fellow members the ropes. Steve passed away on 1st January 2025 after being unwell for quite some time. The Ubuntu Release Team dedicates 25.04 “Plucky Puffin” to our colleague and friend, Steve Langasek. He is missed and will live in our hearts forever. Thank you for everything, Steve.

Upgrades

We’ve identified two issues in the ubuntu-release-upgrader affecting upgrades to Ubuntu 25.04 “Plucky Puffin”:

  • Handling of Qt dependencies
  • Removal of foreign packages from disabled sources As a result, upgrades to Ubuntu 25.04 have been temporarily suspended while these issues are being addressed. The necessary updates are already in the pipeline, and we expect to re-enable upgrades very soon. Thank you for your patience.
Support lifespan

Ubuntu 25.04 will be supported for 9 months until January 2026. If you need long term support, we recommend you use Ubuntu 24.04.2 LTS which is supported until at least 2029.

Upgrades
  • Upgrades to to Ubuntu 25.04 will refresh seeded snaps to the appropriate snap channels, regardless of what was being tracked before. Snaps that are newly-seeded will be installed during the upgrade. In particular, the following snaps will be installed or refreshed on upgrade: Early upgrades may wish to perform these updates manually.
New features in 25.04
Updated Packages
Linux kernel 6.14🐧

This release delivers the latest Linux kernel, following Canonical’s new policy. Kernel developers can now make use of a new scheduling system, “sched_ext”, which provides a mechanism to implement scheduling policies as eBPF programs. This enables developers to defer scheduling decisions to standard user-space programs and implement fully functional hot-swappable Linux schedulers, using any language, tool, library, or resource accessible in user-space. A new NTSYNC driver that emulates WinNT sync primitives is also available, delivering better performance potential for Windows games running on Wine and Proton (Steam Play). The “bpftools” and linux-perf tools have been decoupled from the kernel version, making dependency management easier for developers working with containers. These tools are now shipped in their own packages. Other features can be found in the Linux 6.14 upstream changelog. After the generic kernel grew the ability to tune responsiveness at boot time, the linux-lowlatency binary package has been retired in favour of a combination of linux-generic and a new userspace lowlatency-kernel package, responsible of tuning the grub cmdline.

systemd v257.4

The init system was updated to systemd v257.4. See the upstream changelog for more information about individual features. To highlight a few things:

  • In Ubuntu, systemd is no longer built with utmp support. Among other things, this means that systemd’s default /usr/lib/tmpfiles.d/systemd.conf no longer creates /run/utmp. There is currently this known bug (LP: #2103489) in Ubuntu 25.04, that prevents ‘who’ from properly working and requires a coreutils rebuild.
  • The complete removal of support for cgroup v1 (‘legacy’ and ‘hybrid’ hierarchies) is scheduled for v258.
  • Support for System V service scripts is deprecated and will be removed in v258. Please make sure to update your software now to include a native systemd unit file instead of a legacy System V script to retain compatibility with future systemd releases.
Netplan v1.1.2 🌐

Adding support for wpa-psk-sha256 WiFis and allowing to configure routing-policy on the NetworkManager backend (LP: #2086544). Additionally, the version shipped in Ubuntu enables new functionality in systemd-networkd-wait-online to wait for DNS servers to be configured and reachable, before considering an interface to be online.

Toolchain Upgrades 🛠️
  • GCC 🐄 a snapshot of the upcoming GCC 15, binutils updated to 2.44, and glibc to 2.41.
  • Python 🐍 is updated to 3.13.3
  • LLVM 🐉 now defaults to version 20
  • Rust 🦀 toolchain defaults to version 1.84
  • Golang 🐀 is updated to 1.24
  • OpenJDK ☕ versions 24 GA and 25 early access snapshot are now available
OpenJDK

OpenJDK 21 is still the default. OpenJDK 24 is included as an optional OpenJDK. An early access snapshot of OpenJDK 25 is also included. Support for OpenJDK LTS versions 17, 11 and 8 is being maintained. OpenJDK with CRaC versions 17 and 21 also continue to be supported. We are excited to announce the devpack-for-spring snap and a set of Spring® content snaps that will serve as development tools for Spring® projects. Developers can now quickly build Ubuntu ROCK images for their Java applications using the Gradle and Maven plugins for Rockcraft. Additionally, GraalVM Community Edition for JDK versions 21, 24 and 25ea is now available as a snap. Java developers now have a choice to build and deploy their applications with standard OpenJDK, with OpenJDK-CRaC or as a GraalVM native image.

.NET

.NET versions 8 and 9 continue to be supported. The dotnet snap is updated to include .NET version 9. The powershell-preview snap has been updated to build from source.

Default configuration changes ⚙️
AppArmor profiles
AppArmor profile writing effort

As part of a profile writing effort to improve overall system security, the AppArmor package now includes many new profiles for applications. This improved sandboxing can help mitigate the impact of any exploit in the confined applications. However, these profiles may cause breakage for unanticipated uses of those applications, and we encourage users to file a bug on Launchpad for AppArmor-induced breakage in common use cases. When AppArmor denies an action, it usually generates a log entry describing the denial, which will help us investigate the bug, but which can also be used to add additional rules for customization or to work around the denials. AppArmor log entries can be read in the auditd logs, if auditd is installed, or in the syslog otherwise. This page describes how the information contained in the denial log can be used to update a local override.

AppArmor profile for bwrap

AppArmor now comes with a bwrap profile (bwrap-userns-restrict) that allows it to create user namespaces and set up sandboxing, before transitioning to a tighter profile that denies capabilities for the processes running inside the bwrap sandbox. The addition of this profile should unblock more use cases for bwrap while allowing a reduction in the kernel attack surface opened up by unprivileged user namespaces. However, this profile still restricts unprivileged userns creation and capability usage even when bwrap (and its sandboxed application) are run as a privileged user, so such use cases may not be fully supported yet.

AppArmor profile removals

As part of hardening improvements around AppArmor user namespace mediation, profiles for busybox and nautilus that directly allowed them access to user namespaces have been removed. As a result, the busybox unshare function can no longer be used to create unprivileged user namespaces. Nautilus’ use of user namespaces should still work due to the new bwrap-users-restrict profile, but regressions are possible if there are bugs in the bwrap profile.

tzdata

Previously, the tzdata package in Ubuntu used the /etc/timezone file to configure the system’s timezone. This method is not supported by systemd and certain desktop environments, which instead only change the /etc/localtime symlink to point to a file in /usr/share/zoneinfo. For this reason, starting with version 2024b-5, the tzdata package no longer automatically creates the /etc/timezone file, but still updates it if it exists. In the next Ubuntu 25.10 release, the /etc/timezone file will be automatically removed and support for it in the maintainer scripts will be completely dropped.

Ubuntu Desktop
New ARM64 Desktop Image
  • There is now also an official generic arm64 desktop ISO targeting VMs, ACPI + EFI platforms and Snapdragon based WoA devices.
  • Initial hardware enablement work for the Snapdragon X Elite platform is included in the desktop ISO
Installer and Upgrades
  • Added the option to replace an existing Ubuntu installation
  • Improved dual boot UX (with a focus on BitLocker protected Windows systems):
  • Added the option to install Ubuntu alongside existing BitLocker partitions if enough unallocated space (or a sufficiently large and resizable partition) is available
  • Made encrypted installations and other ‘advanced options’ available for dual boot scenarios
Enterprise
  • authd: Ubuntu’s cloud authentication solution:
  • Many fixes and improvements to the EntraID provider
  • New Google provider
  • New authd documentation
  • New ADSys Release: the Active Directory Group Policy client for Ubuntu, supports the latest Polkit and comes with improvements and bug fixes to certificates enrolment.
GNOME 👣
  • GNOME has been updated to include new features and fixes from the latest GNOME release, GNOME 48
  • GNOME 48 now includes the triple buffering feature from Ubuntu
Default app changes
  • The Document Viewer app for viewing PDFs is now provided by Papers instead of Evince. Papers started with the Evince codebase but it has been updated to use GTK4 and partially rewritten in Rust.
  • xdg-terminal-exec is installed by default making it easier to switch a user’s default terminal for the Ctrl+Alt+T keyboard shortcut and for opening terminal apps (LP: #2107326)
  • Geolocation services are now backed by BeaconDB after Mozilla Location Services was retired last year
  • The JPEG XL format is now supported without needing to install any additional packages
Updated Applications
  • Firefox 137 🔥🦊
  • LibreOffice 25.2 📚
  • Thunderbird 128 “Supernova” 🌩️🐦
  • GNU Image Manipulation Program 3.0 🖼️ is available for install
  • The fish shell has always been known for its smart and user-friendly interface, making command-line interactions more intuitive and efficient. With the release of version 4, fish has undergone a significant transformation, rewritten entirely in Rust. This change brings a on one side the values of the ecosystem like enhanced performance and improved stability, while on the other side is not compromising on the feature set. The upstream community had a great blog about the rust port, which we recommend reading if you are curious. As shells go, this is about your taste and preferences: if you have not been trying fish before, consider to try it out now and experience its features for yourself.
Updated Subsystems
  • BlueZ 5.79 💙
  • Cairo 1.18.4 🐫
  • NetworkManager 1.52 🖧
  • Pipewire 1.2.7 🔊
  • Poppler 25.03 📝
  • xdg-desktop-portal 1.20 ⛩️
  • Nvidia 570 👁️
  • The libva library is now available in the Main repository component. The library implements VA-API (Video Acceleration API) for hardware video decoding and encoding. Applications can now use VA-API out of box. Notably, you can record your screen at the original screen rate. Without VA-API, your screen recording has a reduced frame rate because it’s limited by the CPU. To use VA-API, enable third-party drivers during Ubuntu installation. You can also install the library after installation: sudo apt install va-driver-all
Gaming
NVIDIA Dynamic Boost

This release enabled NVIDIA Dynamic Boost by default on supported laptops with NVIDIA GPUs. …

View originalPermalink
How 25.04 went

24.10

Added 7
  • Linux kernel 6.11 with crash dumps enabled by default for desktop and server installations
  • systemd-ssh-generator binds socket-activated SSH server to local AF_VSOCK and AF_UNIX sockets under certain conditions
  • OpenJDK 23 and OpenJDK 24 early access snapshot are now available
  • .NET 9 is fully supported and available through .NET Backports PPA for Ubuntu 24.04 LTS and 22.04 LTS
  • .NET support extended to IBM Power platform for both .NET 8 and .NET 9
  • New and improved .NET Snap allows installing any supported version of .NET on any Ubuntu system
  • Desktop installer now supports local file paths for autoinstall import
Changed 11
  • OpenSSL updated to version 3.3 with large performance and scalability improvements
  • OpenSSL now loads configuration dropins from /etc/ssl/openssl.conf.d for easier customization
  • systemd updated to v256.5
  • Netplan updated to version 1.1 with custom systemd-networkd-wait-online logic
  • GCC updated to 14.2, binutils to 2.43.1, and glibc to 2.40
  • Python updated to 3.12.7
Removed 1
  • cryptsetup tools split into new systemd-cryptsetup package to reduce dependencies pulled in by main systemd package
Deprecated 2
  • Support for cgroup v1 legacy and hybrid hierarchies is now considered obsolete and systemd will refuse to boot under it by default
  • Support for System V service scripts is deprecated and will be removed in a future release

Ubuntu 24.10 release notes

These release notes for Ubuntu 24.10 (Oracular Oriole) provide an overview of the release and document the known issues with Ubuntu and its flavors.

Support lifespan

Ubuntu 24.10 will be supported for 9 months until July 2025. If you need long term support, we recommend you use Ubuntu 24.04.1 LTS which is supported until at least 2029.

Upgrades
  • Upgrades to to Ubuntu 24.10 will refresh seeded snaps to the appropriate snap channels, regardless of what was being tracked before. Snaps that are newly-seeded will be installed during the upgrade. In particular, the following snaps will be installed or refreshed on upgrade:
  • core24 latest/stable
  • desktop-security-center 1/stable/ubuntu-24.10
  • gnome-46-2404 stable/ubuntu-24.10
  • mesa-2404 stable/ubuntu-24.10
  • prompting-client 1/stable/ubuntu-24.10
  • firefox stable/ubuntu-24.10
  • thunderbird stable/ubuntu-24.10
  • snapd-desktop-integration stable/ubuntu-24.10 Early upgrades may wish to perform these updates manually.
New features in 24.10
Updated Packages
OpenSSL 3.3

OpenSSL has been updated to version 3.3 with large performance and scalability improvements compared to openssl 3.0. It is now also loading configuration dropins from /etc/ssl/openssl.conf.d for easier customisation.

Linux kernel 🐧

Ubuntu 24.10 includes the new 6.11 Linux kernel that brings many new features. Crash dumps are now enabled by default for desktop and server installations. Please refer to the Ubuntu Server Kernel crash dump documentation for complete details. Detailed changes are reported in the Oracular Kernel Release Notes post.

systemd v256.5

The init system was updated to systemd v256.5. See the upstream changelog for more information about individual features. To highlight a few things:

  • Support for cgroup v1 (‘legacy’ and ‘hybrid’ hierarchies) is now considered obsolete and systemd by default will refuse to boot under it. To forcibly reenable cgroup v1 support, SYSTEMD_CGROUP_ENABLE_LEGACY_FORCE=1 must be set on kernel command line.
  • Support for System V service scripts is deprecated and will be removed in a future release. Please make sure to update your software now to include a native systemd unit file instead of a legacy System V script to retain compatibility with future systemd releases.
  • When sshd is installed on a system, a new systemd generator, systemd-ssh-generator binds a socket-activated SSH server to local AF_VSOCK and AF_UNIX sockets under certain conditions. See the man page for more details. Note that this feature is different and indendent from sshd-socket-generator which is shipped in Ubuntu’s openssh-server package.
  • Ubuntu now ships upstream systemd’s tmp.mount by default. In effect this means that /tmp is now a tmpfs by default.
  • cryptsetup tools such as systemd-cryptsetup, systemd-cryptenroll, systemd-veritysetup, and more, have been split into a new systemd-cryptsetup package to reduce dependencies pulled in by the main systemd package. This new package is only listed as a Suggests, so if this functionality is used ensure that either Suggests are installed or that it is manually installed.
  • Ubuntu’s systemd-networkd no longer sets UseDomains=true for managed network interfaces. In effect, this means that search domains configured in DHCP leases will not be reflected in /etc/resolv.conf by default. This change aligns Ubuntu’s default behavior with that of upstream. System administrators may choose to override this default on a global, or per-interface basis. See systemd.network for details.
Netplan v1.1 🌐

The new version 1.1 of Netplan introduces a custom systemd-networkd-wait-online logic, waiting for link-local addresses and one routable interface, as described in the https://discourse.ubuntu.com/t/spec-definition-of-an-online-system/27838. Besides improvements to the embedded-switch-mode setting for SR-IOV devices, the introduction of parser flag to skip broken configurations and fixes for ProtonVPN and Microsoft Azure Linux.

Toolchain Upgrades 🛠️
  • GCC 🐄 is updated to 14.2, binutils to 2.43.1, and glibc to 2.40.
  • Python 🐍 is updated to 3.12.7
  • LLVM 🐉 now defaults to version 19
  • Rust 🦀 toolchain defaults to version 1.80
  • Golang 🐀 is updated to 1.23
  • .NET 9 🤖 now available, .NET 8 support extended to IBM Power
  • OpenJDK ☕ versions 23 and 24 (early access snapshot) are now available
OpenJDK

OpenJDK 21 is still the default. OpenJDK 23 is included as an optional OpenJDK. An early access snapshot of OpenJDK 24 is also included. Support for OpenJDK LTS versions 17, 11 and 8 is being maintained. OpenJDK 21 and OpenJDK 17 packages are now TCK (Technology Compatibility Kit) certified on amd64, arm64, s390x, ppc64el and armhf. The Java TCK is the most comprehensive test suite that covers all aspects of Java SE specification including language features, libraries and APIs. This guarantees interoperability and conformance to standard.

.NET

With the release of .NET 9, Ubuntu reinforces its commitment to supporting the .NET community. .NET 9 is fully supported on Ubuntu 24.10 and is also available for Ubuntu 24.04 LTS (Noble Numbat) and Ubuntu 22.04 LTS (Jammy Jellyfish) through the .NET Backports PPA. In addition, we have expanded .NET support to the IBM Power platform for both .NET 8 and .NET 9, further broadening the platform’s reach. We are also excited to introduce the new and improved .NET Snap, allowing developers to seamlessly install any supported version of .NET on any Ubuntu system.

Default configuration changes ⚙️

As always there are many changes to defaults, mostly by newer versions of packages. But a few are worth spelling out if your former automation, configuration and tuning relied on those settings being one or the other way.

Ubuntu Desktop
Installer and Upgrades
  • The desktop installer now support local file paths for autoinstall import.
  • Power Profiles Manager has been improved and optimized to support better newer hardware features (especially AMD), can now support multiple optimization drivers and is now battery-aware to automatically increase the optimization levels when running on battery only.
  • fprintd has been updated and libfprint supports now many other fingerprint drivers and devices.
Store

The App Center now includes improvements to the Manage page including:

  • Installs in progress
  • Improved self-update handling
  • Messaging for running snaps
  • Direct uninstall of snaps from the manage page
  • Scrolling support for touch screens Third party deb installation is now also supported.
Security Center
  • A new Security Center is included. It features the ability to easily enable or disable a new experimental permissions prompting feature for Home directory permissions.
  • More features will be added in future Ubuntu releases.
  • Prompting is also supported by an additional seeded snap, prompting-client, for permissions prompt handling.
20th Anniversary Celebration

20 years ago, the first version of Ubuntu was released, Ubuntu 4.10 “Warty Warthog”. We are celebrating this monumental anniversary with several temporary flourishes

  • The return of the original startup sound, which can be disabled via Settings > Sound
  • A ‘Warty’ brown accent colour that can be enabled in Settings > Appearance > Style
  • An anniversary logo
GNOME 👣
  • GNOME has been updated to include new features and fixes from the latest GNOME release, GNOME 47.
  • In GNOME Shell and Mutter, Ubuntu includes additional patches to enhance stability and performance, which have not yet been merged upstream.
  • The Ubuntu dock now visualises snap refreshes and includes better handling for PWAs installed via the Chromium snap.
Default app changes
  • The Sysprof app is installed by default as a new system utility. This makes it easier to discover performance issues in your apps.
Updated Applications
  • Firefox 130 🔥🦊
  • LibreOffice 24.8 📚
  • Thunderbird 128 “Supernova” 🌩️🐦
Updated Subsystems
  • BlueZ 5.77 💙
  • Cairo 1.18.2 👁️⃤
  • Noto Color Emoji Font 2.047 with Unicode 16 support 🥳
  • NetworkManager 1.48 🖧
  • Pipewire 1.2.4 🔊
  • Poppler 24.08 📝
  • xdg-desktop-portal 1.18 ⛩️
Nvidia

Ubuntu 24.10 now defaults to Wayland instead of Xorg on machines using Nvidia graphics. If you require Xorg instead then select ‘Ubuntu on Xorg’ from the session menu on the login screen.

Ubuntu WSL

Ubuntu Server
Apache2

Apache2 has been updated from Noble’s 2.4.58 to the current 2.4.62, and some of the more noteworthy changes include:

  • htpasswd: Add support for passwords using SHA-2.
  • core: Allow mod_env to override system environment vars.
  • mod_xml2enc: Update check to accept any text/ media type or any XML media type per RFC 7303, avoiding corruption of Microsoft OOXML formats.
  • mod_ssl: SSLProxyMachineCertificateFile/Path may reference files which include CA certificates; those CA certs are treated as if configured with SSLProxyMachineCertificateChainFile.
  • mod_ssl: Improve compatibility with OpenSSL 3, including handling when OPENSSL_NO_ENGINE is set and support for loading certs/keys from pkcs11.
  • mod_proxy: Ignore (and warn about) enablereuse=on for ProxyPassMatch when some dollar substitution (backreference) happens in the hostname or port part of the URL.
  • mod_proxy: Add optional third argument for ProxyRemote, which configures Basic authentication credentials to pass to the remote proxy.
  • mod_md: Certificate renewals are triggerable using OCSP stapling information. For more details, please see the full set of changes.
Clamav

Clamav is updated from version 1.0.5 to 1.3.1 in Oracular, bringing significant improvements and changes, including:

  • Added support for extracting and scanning attachments found in Microsoft OneNote section files.
  • Added support for extracting Universal Disk Format (UDF) partitions.
  • Added a –cache-size option to customize the size of ClamAV’s clean file cache, which may improve scan performance at the expense of more RAM.
  • Introduced a customizable SystemD timer for running Freshclam updates, without sending Freshclam into the background.
  • Refined limit handling for large files
  • Added ability for Freshclam to use a client certificate PEM file and a private key PEM file for authentication to a private mirror
  • Added the ability to extract images embedded in HTML CSS blocks.
  • Enhancements relating to VBA extraction from office documents
  • Added support for aborting on standup if virus database is older than a configured number of days. For a comprehensive listing of changes included since Ubuntu Noble, please see the changelogs for 1.1.0, 1.2.0, 1.3.0, and 1.3.1.
Chrony

The chrony package in Oracular was changed to no longer ship the default Ubuntu NTP pools in /etc/chrony/chrony.conf. A new snippet configuration file is created in /etc/chrony/sources.d/ubuntu-ntp-pools.sources defining those servers. The motivation for this change is explained in LP: #2048876. If you changed your chrony.conf, an upgrade to this version will stop at a dpkg config prompt, showing the differences between the installed file and the new one. If you chose to keep the existing chrony.conf, keep in mind that the Ubuntu NTP pools from /etc/chrony/sources.d/ubuntu-ntp-pools.sources will also be used. @ankushpathak wrote a great post about this change: https://discourse.ubuntu.com/t/improving-chrony-time-source-configuration-in-ubuntu/47850

cloud-init v. 24.3.1

Notable features beyond v. 24.1 present in Noble:

  • Bootspeed improvement: support for socket-based shared python process across cloud-init boot stages (#5595)
  • NoCloud support for FTP and FTP over TLS (#4834)
  • Add network-config seed support for nocloud datasource (#5566)
  • Network v2 schema validation (#4892)
  • Add support for disk setup of nvme devices (#5263)
  • Support remote URI sources write_files module (#5505) …
View originalPermalink
How 24.10 went

24.04

LTS
Added 6
  • Year 2038 support for the armhf architecture by updating over a thousand packages to handle time using 64-bit values instead of 32-bit ones
  • Apport integration with systemd-coredump to handle crashes and allow developers to use coredumpctl to analyze crash data
  • OpenJDK 17 and 21 are TCK certified to adhere to Java standards and ensure interoperability with other Java platforms
  • FIPS-compliant OpenJDK 11 package available for Ubuntu Pro users
  • Default AppArmor profiles provided for common applications and frameworks that allow unprivileged user namespaces use
  • New unconfined profile mode and flag added to AppArmor to designate profiles to act like unconfined mode with additional permissions
Changed 12
  • Linux kernel updated to version 6.8
  • systemd updated to version 255.4
  • Netplan updated to version 1.0 with support for simultaneous WPA2 and WPA3, Mellanox VF-LAG for SR-IOV networking, VXLAN improvements, stable libnetplan1 API, and netplan status --diff sub-command
  • GCC updated to version 14
  • binutils updated to version 2.42
  • glibc updated to version 2.39
Security 2
  • .NET 8 support extended to the IBM System Z platform
  • Ubuntu kernel restricts the use of unprivileged user namespaces in combination with AppArmor to mitigate attack surface

Ubuntu 24.04 LTS release notes

These release notes for Ubuntu 24.04 LTS (Noble Numbat) provide an overview of the release and document the known issues with Ubuntu and its flavors. For details of the changes applied since 24.04, refer to the following changelogs:

  • 24.04.4
  • 24.04.3
  • 24.04.2
  • 24.04.1 For the release schedule of Ubuntu 24.04 LTS and its point releases, refer to:
  • Release schedule
Support lifespan

Ubuntu 24.04 LTS will be security maintained for 5 years until 31 May 2029. Users can choose to extend this to 10 years with Ubuntu Pro or 12 years with the Legacy add-on.

Upgrades

Users of Ubuntu 23.10 have been offered an automatic upgrade to 24.04 since shortly after the release. Users of 22.04 LTS will also start being offered the automatic upgrade now that 24.04.1 LTS has been released.

Changes since 22.04 LTS

If you’re upgrading from Ubuntu 22.04 LTS to 24.04 LTS, you get all the changes that happened in the six months since Ubuntu 23.10, as well as the changes in all the interim releases between 22.04 LTS and 24.04 LTS. For details, see the complete interim release notes: 22.10, 23.04 and 23.10. Finally, review the following changes since Ubuntu 23.10.

New features in 24.04 LTS
Year 2038 support for the armhf architecture

Ubuntu 24.04 LTS solves the Year 2038 problem that existed on armhf. More than a thousand packages have been updated to handle time using a 64-bit value rather than a 32-bit one, making it possible to handle times up to 292 billion years in the future.

Updated Packages
Linux kernel 🐧

Ubuntu 24.04 LTS includes the new 6.8 Linux kernel that brings many new features. Detailed changes are reported in the Noble Kernel Release Notes post.

systemd v255.4

The init system was updated to systemd v255.4. See the upstream changelog for more information about individual features.

Netplan v1.0 🌐

The network stack was updated to Netplan version 1.0. Supporting simultaneous WPA2 & WPA3, Mellanox VF-LAG for high-performance SR-IOV networking and VXLAN improvements. It also provides a stable libnetplan1 API and a new netplan status --diff sub-command to find differences between configuration and system state. For more information please see the Introducing Netplan v1.0 blog post.

Toolchain Upgrades 🛠️
  • GCC 🐄 is updated to the 14, binutils to 2.42, and glibc to 2.39.
  • Python 🐍 now defaults to version 3.12
  • OpenJDK ☕ now defaults to LTS version 21
  • LLVM 🐉 now defaults to version 18
  • Rust 🦀 toolchain defaults to version 1.75
  • Golang 🐀 is updated to 1.22
  • .NET 8 is now default
OpenJDK

OpenJDK LTS 21 is the default in Ubuntu 24.04 LTS while maintaining support for versions 17, 11, and 8. OpenJDK 17 and 21 are also TCK certified, which means they adhere to Java standards and ensure interoperability with other Java platforms. A special FIPS-compliant OpenJDK 11 package is also available for Ubuntu Pro users.

.NET

With the introduction of .NET 8, Ubuntu is taking a significant step forward in supporting the .NET community. .NET 8 will be fully supported on Ubuntu 24.04 LTS and 22.04 LTS for the entire lifecycle of both releases. This enables developers to upgrade their applications to newer .NET versions before upgrading their Ubuntu release. Starting with 24.04 LTS the .NET support has also been extended to the IBM System Z platform. .NET 6 and .NET 7 packages with limited support are available via a PPA.

Apport

Apport added integration with systemd-coredump to handle crashes. Developers on Ubuntu can co-install systemd-coredump now and use coredumpctl to analyze crash data. Apport will continue to collect crash information and submit it to the Ubuntu Error Tracker and Launchpad.

Security Improvements 🔒
Unprivileged user namespace restrictions

In combination with the apparmor package, the Ubuntu kernel now restricts the use of unprivileged user namespaces. This affects all programs on the system that are unprivileged and unconfined. A default AppArmor profile is provided that allows the use of user namespaces for unprivileged and unconfined applications but will deny the subsequent use of any capabilities within the user namespace. A common use-case for unprivileged user namespaces is applications that construct their own sandboxes or work with styles of container workloads. As such, AppArmor profiles that allow the use of unprivileged user namespaces are also provided for common applications and frameworks that come from the Ubuntu archive, as well as popular third party applications like Google Chrome, Discord and others. This is a subsequent step towards trying to mitigate the larger attack surface presented by unprivileged user namespaces (the first being the introduction of this feature in Ubuntu 23.10 where it was not enabled by default). Whilst significant effort has been expended to try and identify all applications that may require such profiles, it is expected that there may be cases where additional profiles are required. In this case, there are several options if you run into problems:

  • Confine your applications with an AppArmor profile. Because this can be potentially onerous, a new unconfined profile mode/flag has been added to AppArmor. This designates the profile to essentially act like the unconfined mode for AppArmor where an application is not restricted, and it allows additional permissions to be added, such as the userns, permission. Such profile for, e.g. Google Chrome, would look like the following, and it would be located within the /etc/apparmor.d/chrome file: abi <abi/4.0>, include <tunables/global> /opt/google/chrome/chrome flags=(unconfined) { userns, # Site-specific additions and overrides. See local/README for details. include if exists <local/chrome> } Alternatively, a complete AppArmor profile for the application can be created (see the AppArmor documentation).
  • Launch your application in a way that doesn’t use unprivileged user namespaces, e.g. google-chrome-stable --no-sandbox. However, since this disables the use of an internal security feature within the application, this is not recommended. Instead, use the unconfined profile mode described above instead.
  • Disable this restriction on the entire system for one boot by executing echo 0 | sudo tee /proc/sys/kernel/apparmor_restrict_unprivileged_userns. This setting is lost on reboot. This similar to the previous behaviour, but it does not mitigate against kernel exploits that abuse the unprivileged user namespaces feature.
  • Disable this restriction using a persistent setting by adding a new file (/etc/sysctl.d/60-apparmor-namespace.conf) with the following contents: kernel.apparmor_restrict_unprivileged_userns=0 Reboot. This is similar to the previous behaviour, but it does not mitigate against kernel exploits that abuse the unprivileged user namespaces feature.
TLS 1.0, 1.1 and DTLS 1.0 are forcefully disabled
  • for software using openssl this was the case since 20.04
  • for software using gnutls, this is now enforced (with openconnect being a notable exception)
More consistent application of openssl and gnutls system configurations

Some libraries do not raise errors when their configuration is not accessible; this could happen when AppArmor does not allow access to the configuration files. Due to how widespread openssl and gnutls are, the AppArmor rules now grant access to their configuration files by default. Their system-wide configuration will therefore be followed better.

Deprecation and disablement of 1024-bit RSA APT repository signing keys

APT in 24.04 requires repositories to be signed with the RSA keys no smaller than 2048 bits, Ed25519, or Ed448. As work to resign old Launchpad PPAs with a stronger keys is still ongoing for some weeks, this is initially only a warning. Once Launchpad PPAs have been resigned, you will need to manually migrate any affected PPAs to new signing keys by removing and re-adding them to quiesce the warning. The final APT 2.8.0 release that converts the warning to an error should be published as a stable release update some time after the resigning is complete.

pptpd removed
  • pptpd and bcrelay have been removed
OpenSSH with reduced dependencies

As per the XZ-utils backdoor, openssh in Ubuntu does not depend anymore on libsystemd, reducing the number of dependencies and making it less prone to future security issues.

Package security-hardening improvements

Packages are now built with security-hardening features which stop many undiscovered security vulnerabilities, rendering them unexploitable. The gcc compiler and dpkg now defaults to -D_FORTIFY_SOURCE=3 instead of -D_FORTIFY_SOURCE=2 which greatly increases buffer overflow detection and mitigation. dpkg now defaults to use -mbranch-protection=standard which mitigates code reuse attacks on arm64.

Performance ⚡
Performance Engineering tools

A set of performance engineering tools is installed by default on relevant Ubuntu systems. Additionally, a performance-tools metapackage has been created to assist in debugging performance and reliability issues. See specification for more details.

Default configuration changes ⚙️

As always there are many changes to defaults, mostly by newer versions of packages. But a few are worth spelling out if your former automation, configuration and tuning relied on those settings being one or the other way.

Apt priority of the proposed pocket

The proposed pocket is used as a staging area for software updates. These updates land in the proposed pocket before they are released to the wider public userbase. But in the past, if someone enabled the proposed pocket for testing they often got into trouble by getting their system flooded with everything that is in the proposed pocket. If just one of the packages in there was weirdly broken you’d have been broken by that as well - and it might have been unrelated to what you really care about and made your regular testing consume more effort and thereby less attractive. By changing the default priority, users are less likely to install potentially unstable updates unintentionally. Therefore the default apt priority of the proposed pocket was reduced from 500 to 100. This change already happened in Ubuntu Lunar, but Noble is the first Ubuntu LTS to pick it up and therefore there is much more time of consumption from the proposed pocket in front of it. With the change, users can now selectively install packages from the proposed pocket. This allows for more conscious selection and testing of updates. You can always see the new versions of the packages e.g. via apt-cache policy but they will no more auto-install. To install a package from proposed you’d now need to select from which pocket you want to install like apt install /-proposed The above helps a lot for the conscious testing of changes. But on the other hand having automation and people testing (almost) all new package versions regularly can provide great signal. Especially in canary setup with their very own workload it can prevent breaking these specific setup unintentionally as it might be different from what is tested elsewhere. Therefore in those situations if you want to go back to the old behavior of just getting everything from proposed all the time, you’d need to bump the apt pin priority back up to 500 so the versions from the proposed pocket compete on the same level with the rest of the Ubuntu Archive. To do that you could put the following in a file like /etc/apt/preferences.d/bump-proposed-prio:

Consider proposed all the time, set default priority 500 Package: * Pin: release a=noble-proposed Pin-Priority: 500

deb822 sources management

The sources configuration for Ubuntu has moved from /etc/apt/sources.list to /etc/apt/sources.list.d/ubuntu.sources in the more featureful deb822 format, aligning with PPAs that already migrated to deb822 last year. See the specification for more details. …

View originalPermalink
How 24.04 went

22.04

LTS
Added 3
  • Ubuntu 22.04 LTS ships with Linux kernel v5.17 on latest certified desktop devices and rolling HWE kernel based on v5.15 on other hardware generations
  • systemd-oomd package is now shipped by default on Ubuntu Desktop flavor to avoid overloaded systems
  • OpenJDK 18 is now provided in addition to OpenJDK 11
Changed 11
  • GCC was updated to 11.2.0, binutils to 2.38, and glibc to 2.35
  • Python now ships at version 3.10.4
  • Perl was updated to version 5.34.0
  • LLVM now defaults to version 14
  • golang defaults to version 1.18.x
  • rustc defaults to version 1.58
Fixed 1
  • UDP is disabled for NFS mounts via kernel option CONFIG_NFS_DISABLE_UDP_SUPPORT=y to prevent mount errors

Ubuntu 22.04 LTS release notes

These release notes for Ubuntu 22.04 LTS (Jammy Jellyfish) provide an overview of the release and document the known issues with Ubuntu and its flavors. For details of the changes applied since 20.04, refer to the following posts:

  • 22.04.5
  • 22.04.4
  • 22.04.3
  • 22.04.2
  • 22.04.1 For the release schedule of Ubuntu 22.04 LTS and its point releases, refer to:
  • Release schedule
Support lifespan

Maintenance updates will be provided for 5 years until April 2027 for Ubuntu Desktop, Ubuntu Server, Ubuntu Cloud, and Ubuntu Core. All the remaining flavors will be supported for 3 years. Additional security support is available with ESM (Extended Security Maintenance).

Get Ubuntu 22.04 LTS

Images can be downloaded from a location near you. You can download ISOs and flashable images from:

  • Ubuntu Desktop and Server for 64-bit x86 (AMD64)
  • Less Frequently Downloaded Ubuntu Images
  • Ubuntu Cloud Images
  • Lubuntu
  • Kubuntu
  • Ubuntu Budgie
  • Ubuntu Kylin
  • Ubuntu MATE
  • Ubuntu Studio
  • Xubuntu
Upgrading from Ubuntu 21.10

To upgrade on a desktop system:

  • Open the “Software & Updates” Setting in System Settings.
  • Select the 3rd Tab called “Updates”.
  • Set the “Notify me of a new Ubuntu version” dropdown menu to “For any new version”.
  • Press Alt+F2 and type in update-manager -c into the command box.
  • Update Manager should open up and tell you: “New distribution release ‘22.04’ is available.”
  • If not you can also use /usr/lib/ubuntu-release-upgrader/check-new-release-gtk
  • Click Upgrade and follow the on-screen instructions. To upgrade on a server system:
  • Make sure the Prompt line in /etc/update-manager/release-upgrades is set to normal.
  • Launch the upgrade tool with the command sudo do-release-upgrade.
  • Follow the on-screen instructions. Note that the server upgrade will use GNU screen and automatically re-attach in case of dropped connection problems. There are no offline upgrade options for Ubuntu Desktop and Ubuntu Server. Please ensure you have network connectivity to one of the official mirrors or to a locally accessible mirror and follow the instructions above.
Changes since 20.04 LTS

If you’re upgrading from Ubuntu 20.04 LTS to 22.04 LTS, you get all the changes that happened in the six months since Ubuntu 21.10, as well as the changes in all the interim releases between 20.04 LTS and 22.04 LTS. For details, see the complete interim release notes: 20.10, 21.04 and 21.10. Finally, review the following changes since Ubuntu 21.10.

New features in 22.04 LTS
Updated Packages
Linux kernel 🐧

Ubuntu 22.04 LTS ships multiple optimized kernels on per-product basis:

  • Ubuntu Desktop will automatically opt-into v5.17 kernel on the latest generations of certified devices (linux-oem-22.04)
  • Ubuntu Desktop uses a rolling HWE kernel (linux-hwe-22.04) on all other generations of hardware. The rolling HWE kernel is based on the v5.15 kernel for 22.04.0 and 22.04.1 point releases
  • Ubuntu Server defaults to a non-rolling LTS kernel v5.15 (linux-generic)
  • Ubuntu Cloud and Devices use optimized kernels in collaboration with partners (v5.15+ with additional backports and features) Additional optimized and certified kernel flavors will become available in Ubuntu 22.04 LTS in due course.
UDP disabled for NFS mounts

Since Ubuntu 20.10 (Groovy Gorilla), the kernel option CONFIG_NFS_DISABLE_UDP_SUPPORT=y is set and this disables using UDP as the transport for NFS mounts, regardless of NFS version. In practice, if you try to use udp, you will get this error: $ sudo mount f1:/storage /mnt -o udp mount.nfs: an incorrect mount option was specified

Toolchain Upgrades 🛠️

GCC was updated to the 11.2.0 release, binutils to 2.38, and glibc to 2.35. Python 🐍 now ships at version 3.10.4, Perl 🐪 at version 5.34.0. LLVM now defaults to version 14. golang defaults to version 1.18.x. rustc defaults to version 1.58. In addition to OpenJDK 11, OpenJDK 18 is now provided (but not used for package builds). Ruby 💎 was updated from v2.7.4 to v3.0.

systemd v249.11

The init system was updated to systemd v249, using a solid .11 patchlevel for the LTS. Please refer to the upstream changelog for more information about the individual features. We’ve enabled the userspace OOMD service and are shipping the systemd-oomd package by default on the “Ubuntu Desktop” flavor, to avoid overloaded systems and the need of the kernel’s OOM killer to kick in. The OOMD status can be checked using oomctl.

OpenSSL 3.0

We’ve upgraded the OpenSSL library to the new 3.0 version, which disables a lot of legacy algorithms by default, as detailed in their migration guide. In particular, certificates using SHA1 or MD5 as hash algorithms are now invalid under the default security level. In addition to the upstream deprecations, please note that since Ubuntu 20.04 LTS (Focal Fossa), the security level 2 (which is the default) disables the (D)TLS protocols below 1.2 (included). Since the new version has an API bump, third-party packages that depend on libssl1.1 will need to be rebuilt to instead depend on libssl3, as the older ABI isn’t provided anymore.

plocate

plocate is now the default locate implementation, replacing mlocate. The mlocate package is now a transitional package and will install plocate. plocate is largely argument-compatible with mlocate, but some incompatibilities do exist. For details, see the manual for plocate.

Security Improvements 🔒

nftables is now the default backend for the firewall. All applications on the system must agree on whether they will use the legacy xtables backend or the newer nftables backend. Bug 1968608 provides some context that may be helpful. Docker may not be ready for the new nftables backend. ssh-rsa is now disabled by default in OpenSSH. See bug 1961833 to learn how to selectively re-enable it if necessary. If you are upgrading a system remotely over SSH, you should check that you are not relying on this to ensure that you will retain access after the upgrade. scp offers a -s command line option to use sftp mode rather than scp mode when handling remote filenames. This new, safer, behaviour will eventually become the default.

Ubuntu Desktop
  • Ubuntu now offers 10 color choices each in dark and light styles
  • Firefox is now only provided in Ubuntu as a snap. Some benefits include
  • Directly maintained by Mozilla
  • More maintainable for the entire Ubuntu LTS lifecycle
  • … Which means faster access to the newest Firefox versions
  • Easily switch to a different Firefox flavor with snap channels including esr/stable, latest/candidate, latest/beta, and latest/edge
  • Sandboxed for improved security hardening for this critical app
  • Improved in 22.04.1: Firefox startup speed is significantly faster now compared to the original Ubuntu 22.04 LTS release.
  • Desktop icons are shown in the bottom right by default but this can be changed through new settings added to the Appearance panel of the Settings app.
  • Also there are new settings to control the Dock look and behavior
  • Dock devices and filemanager integration has been improved
GNOME 👣
  • GNOME has been updated to include new features and fixes from GNOME 41 and GNOME 42
  • Several apps are still at their 41 version numbers to provide a more time-tested experience for the LTS desktop by mostly avoiding libadwaita.
  • The new cross-desktop dark style preference is supported.
  • GNOME Shell and mutter have lots of performance improvements including the triple buffering patch.
  • The default session for most systems that don’t have an Nvidia desktop graphics card is now Wayland. If you need a non-Wayland session, you can choose the Ubuntu on Xorg session by clicking the gear button after selecting your name on the login screen.
  • Hardware with privacy screen support is now supported
  • RDP is now available for sharing your desktop remotely. Legacy VNC is still available, but it is strongly recommended to use RDP for better security, privacy, and performance. If you were previously using VNC, you’ll need to manually re-enable desktop sharing in the Settings app and get your new login information.
Updated Applications
  • Firefox 103 🔥🦊
  • LibreOffice 7.3 📚
  • Thunderbird 91 🌩️🐦
Updated Subsystems
  • BlueZ 5.63
  • CUPS 2.4
  • NetworkManager 1.36
  • Mesa 22
  • Poppler 22.02
  • PulseAudio 16
  • xdg-desktop-portal 1.14
Ubuntu Server
Ubuntu HA/Clustering
Corosync

It was updated to version 3.16 which includes some new features:

  • Support for changing crypto configuration during runtime. This includes turning cryptography on or off, changing crypto_cipher and crypto_hash and also changing of crypto key.
  • Default token timeout was changed from 1 seconds to 3 seconds.
  • Run corosync -v to get the list of supported crypto and compression models which can be used in corosync.conf
  • Cgroup v2 support. For the complete list of changes please refer to the upstream release notes.
Pacemaker

It was updated to version 2.1.2 which includes some new features:

  • Add a new feature priority-fencing-delay. Optionally derive the priority of a node from the resource-priorities of the resources it is running.
  • Add on-fail=demote and no-quorum-policy=demote recovery policies for promoted resources.
  • support for OCF Resource Agent API 1.1 standard.
  • Many improvements in crm_mon and crm_resource. For the complete list of changes please refer to the upstream release notes. A notable difference from the version in Ubuntu Focal 20.04 is that the default configuration file does not define the node name as node1 anymore, now the output of uname -n is used as the default node name.
Resource agents

It was updated to version 4.7.0. Check the list of changes since Ubuntu Focal 20.04 here. The agents are now separated in two packages: resource-agents-base and resource-agents-extra. The resource-agents-base package contains the agents which are curated by the Ubuntu Server team, which means that automated tests are running in a continuous integration system to guarantee the quality of those agents. The resource-agents package is now a metapackage which depends on both resource-agents-base and resource-agents-extra. Please note that the resource-agents package will be removed in future releases; we recommend that you do not rely on its existence.

Fence agents

It was updated to version 4.7.1. The agents are now separated in two packages: fence-agents-base and fence-agents-extra. The fence-agents-base package contains the agents which are curated by the Ubuntu Server team, which means that automated tests are running in a continuous integration system to guarantee the quality of those agents. The fence-agents package is now a metapackage which depends on both fence-agents-base and fence-agents-extra. Please note that fence-agents will be removed in releases; we recommend that you do not rely on its existence.

Containers runtime
containerd

It was updated to version 1.5.9. Some interesting changes are:

  • Update pull to handle of non-https urls in descriptors
  • Install AppArmor parser for arm64 and update seccomp to 2.5.1
  • Add support for clone3 syscall to fix issue with certain images when seccomp is enabled
  • Add image config labels in CRI container creation For the complete list of changes please refer to the upstream release page.
runc

It was updated to version 1.1.0. There are many improvements and bug fixes which can be found in the upstream release page. Some deprecations and removals which might impact the upgrade are presented below: Deprecation

  • runc run/start now warns if a new container cgroup is non-empty or frozen; this warning will become an error in runc 1.2 Removals
  • cgroup.GetHugePageSizes has been removed entirely, and been replaced with cgroup.HugePageSizes which is more efficient
  • intelrdt.GetIntelRdtPath has been removed. Users who were using this function to get the intelrdt root should use the new intelrdt.Root instead. …
View originalPermalink
How 22.04 went
View all

Discussion