Ubuntu 26.10 changes how systems boot when Secure Boot is enabled by shipping a slimmed, signed GRUB that no longer understands many filesystem and partition formats for /boot. On Secure Boot systems GRUB will not read /boot stored on Btrfs, XFS, ZFS, LVM, LUKS-encrypted volumes or software RAID (except RAID1); HFS+, Apple partition table parsing and JPEG/PNG image loading are also removed. Supported /boot layouts under Secure Boot are limited to ext4, FAT and ISO9660 (and squashfs remains available for snaps). If Secure Boot is disabled the full GRUB feature set, including custom backgrounds and exotic /boot setups, continues to function.
The motivation is security: parsers that probe filesystems and partition tables have been a recurring source of Secure Boot bypasses, and reducing the number of parsers running before the kernel loads shrinks the attack surface. Systems with custom /boot setups must be checked before upgrading; those requiring both Secure Boot and full GRUB functionality are advised to remain on Ubuntu 26.04 LTS (longer supported). Most users installed with the standard installer layout won’t be affected, and LVM, RAID, LUKS, Btrfs and ZFS remain usable once the OS has booted.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.