Tec Nikan
فارسی
Talk to us
All news

Ubuntu Core 26 Offers Fifteen Years of Maintenance and Rebootless ARM64 Patching

A new delta update format cuts over-the-air payloads by 50% to 90%, and live kernel patching reaches ARM64 for the first time.

embedded LinuxUbuntu Coredevice managementOTA updatesedge computing

Canonical announced general availability of Ubuntu Core 26 on 19 May 2026, offering up to 15 years of security maintenance for embedded, IoT and industrial devices.

Three changes matter to anyone running a device fleet. The first is update size: a new snap-delta format cuts over-the-air download sizes by 50% to 90% for most snaps, with Core base snap updates dropping from 16 MB to 1.5 MB. On a fleet behind metered cellular links that is the difference between patching monthly and patching when somebody can justify the data bill.

The second is Canonical Livepatch gaining ARM64 support for the first time, allowing critical and high-severity kernel vulnerabilities to be patched without a reboot. A reboot on an industrial gateway is not free — it is a gap in data collection, and on some sites it needs a maintenance window and a person present.

The third is key handling. Full disk encryption now stores TPM-sealed keys directly in the LUKS2 header, and native OP-TEE integration seals and unseals keys through an ARM TrustZone trusted execution environment. That gives a hardware-anchored answer to the question of how data on the device is protected at rest, which is increasingly asked in procurement rather than only in security reviews.

Alongside those, a Chisel-based build system reduces base image size by 7% and adds explicit dependency traceability, and fleet logs and metrics stream into the Canonical Observability Stack built on Grafana, Loki and Prometheus. Renesas RZ-family microprocessors are among the supported hardware.

The pattern across this release and the Yocto one published a week earlier is the same: the embedded Linux ecosystem is converging on long maintenance windows, machine-readable component inventories and update mechanisms that assume a bad network. All three are answers to the same pressure, which is that connected products are now expected to be maintained for as long as they are in service.

Source: Canonical

Want to work with us?

Tell us what you're building and we'll help you scope the first deployment.