Canonical has changed how Ubuntu 26.10 boots on system with Secure Boot enabled, in an effort to reduce the attack surface of the boot process.
Ubuntu 26.10’s signed build of GRUB, which is only used on systems if Secure Boot is turned on, no longer supports /boot on Btrfs, XFS, ZFS, LVM, LUKS encryption or software RAID (other than RAID1).
HFS+, Apple partition table support and JPEG and PNG image loading is also removed.
Since GRUB needs to read the /boot directory to load the kernel and boot Ubuntu, if those files are on one of the affected filesystems, it can’t access them and the system won’t boot.
Ubuntu 26.10 still supports /boot on ext4, FAT and ISO9660 (used for booting from CD/DVDs), as well as, naturally, squashfs for snaps with Secure Boot enabled
If Secure Boot is disabled, GRUB’s full feature set is loaded, meaning exotic /boot setups and any GRUB customisation tweaks, like image backgrounds work as normal.
Why is Canonical making this change?
Canonical shared its plans to slim down GRUB earlier this year. Feedback to that was testy, to put it politely, as some users with bespoke boot-setups – some created via ‘experimental’ features in the OS installer – weren’t thrilled to hear they may be unable to boot.
Which is why Canonical has made this change after an LTS; those who need Secure Boot and the full GRUB functionality can stick with Ubuntu 26.04 LTS. That version is supported until 2036 with Ubuntu Pro or 2041 with Ubuntu Pro and the Legacy Add-on.
Security is the aim here.
GRUB is the earliest part of the Ubuntu boot chain. In a standard Secure Boot setup, device firmware loads a program called shim, which verifies and loads GRUB. Parsers then probe for filesystems and partition layouts to read from, fine the kernel and load it.
But those parsers have been a source of numerous Secure Boot bypass vulnerabilities in recent years – LLMs are making vulnerabilities faster to find and, potentially, exploit.
Canonical reason that having fewer parsers running before the kernel loads reduces the opportunites to break the ‘chain of trust’ that secures booting.
Most users will not be affected
As dramatic a change as this sounds, it only affects booting Ubuntu 26.10 on a device with Secure Boot enabled, and only affects the boot path itself.
LVM, RAID, LUKS, Btrfs and ZFS remain available to use and access in Ubuntu 26.10 on systems with Secure Boot enabled – just, only once it’s booted.
If you’re worried this will affect you, check for any customised /boot layout against the list of supported types (above) before you upgrade to 26.10 later month.
However, most of Ubuntu users will not be affected since the standard OS installer sets things up in a standard – secure boot friendly – manner.