Ubuntu Completes Its "Oxidation": The Final Shift to Rust-Based Core Utilities

Ubuntu’s long-standing journey toward memory safety has reached a significant milestone. With the upcoming release of Ubuntu 26.10, Canonical has finalized the transition of the foundational GNU Core Utilities to their Rust-based counterparts, known as uutils. This move marks the end of an era, as the iconic cp, mv, and rm commands—previously the last holdouts of the traditional GNU toolchain—are now powered by the uutils implementation.
This shift represents more than just a change in code; it is a fundamental architectural evolution for one of the world’s most popular Linux distributions. By embracing the Rust programming language, Canonical is aggressively tackling the class of memory-safety vulnerabilities that have plagued software development for decades.
The Main Facts: Closing the Loop on Core Utilities
The transition to uutils is a massive undertaking. The GNU Core Utilities (coreutils) form the backbone of any Linux system, handling basic file, shell, and text manipulation. Replacing these with a Rust-based implementation is not merely a matter of swapping binaries; it requires ensuring absolute functional parity with decades-old, battle-tested utilities.
As of Ubuntu 26.10, the migration is complete. While most of the standard toolset—including ls, cat, chmod, and du—had already been integrated into the default stack in earlier releases, the "big three" file-handling commands (cp, mv, and rm) remained on the GNU versions throughout the 26.04 LTS cycle.
The primary reason for this delay was a series of complex technical hurdles, specifically regarding Time-of-Check to Time-of-Use (TOCTOU) race conditions. These issues were identified during rigorous security audits, proving that the transition was not about speed, but about stability and security.

A Chronology of the "Oxidation" Effort
The project to "oxidize" Ubuntu—a term affectionately coined by the community and embraced by Canonical developers—did not happen overnight. It is the culmination of a multi-year strategy aimed at hardening the Linux ecosystem against memory-related bugs.
2025: The Foundation
The journey gained significant momentum last year when Ubuntu 25.10 debuted as the first release to ship the majority of uutils as the default. This release also saw the introduction of sudo-rs, a Rust-based rewrite of the ubiquitous sudo utility. This was a symbolic and practical turning point, demonstrating that Canonical was serious about replacing even the most entrenched C-based tools.
2026: The Audit and the Stall
The release of Ubuntu 26.04 marked a deliberate pause in the transition. Canonical chose not to force the migration of cp, mv, and rm because of unresolved security concerns. During this period, Canonical commissioned a comprehensive, two-round security audit by the firm Zellic. Conducted between December 2025 and March 2026, the audit focused on the most critical utilities. The results were telling: 113 issues were identified, with 44 being severe enough to warrant CVE (Common Vulnerabilities and Exposures) tracking.
Late 2026: Final Implementation
Following the remediation of those vulnerabilities, the path was clear. Despite a brief hiccup in July where the uutils version of cp caused issues with live image builds, the engineering team quickly pushed a fix upstream. With the "critical" tag assigned to the fix, the migration was successfully finalized in time for the Ubuntu 26.10 cycle.
Supporting Data: Why Rust Matters
The move to Rust is not a trend-chasing exercise. It is a strategic response to the realities of modern software security. According to data from major tech companies, including Microsoft and Google, approximately 70% of all severe security vulnerabilities in large-scale software are related to memory safety—issues like buffer overflows, use-after-free, and dangling pointers.

Rust’s compiler-enforced memory safety model eliminates these vulnerabilities at the source. By rewriting core utilities in Rust, Canonical is effectively "immunizing" these essential tools against entire categories of attacks. The 44 CVEs identified during the Zellic audit highlight just how many hidden bugs can exist even in highly scrutinized codebases. By shifting to uutils, Ubuntu is not just replacing code; it is reducing the attack surface of the entire operating system.
Official Responses and Developer Philosophy
Canonical’s approach has been characterized by extreme caution. In various posts on the Ubuntu Discourse forums, developers have emphasized that they are not interested in "blindly" replacing software. The goal is to build a more resilient system without sacrificing the compatibility that users expect.
The uutils project itself maintains a philosophy that any divergence from the behavior of the original GNU utilities is considered a bug. For the average user, the command-line interface remains identical. cp, mv, and rm behave exactly as they did before, ensuring that existing scripts, automation pipelines, and user workflows remain uninterrupted.
For users who prefer the legacy GNU implementation, Canonical has provided a clear exit ramp. The coreutils-from-gnu package remains available in the repository, allowing users to revert to the traditional binaries if they encounter edge cases or specific compatibility requirements that the Rust versions do not yet perfectly emulate.
Implications for the Linux Ecosystem
The completion of this transition has far-reaching implications for the broader Linux community.

1. The Standard of Modern Security
Ubuntu, as a flagship distribution, often sets the standard for enterprise and consumer Linux deployments. By making uutils the default, Canonical is signaling that memory-safe languages are now a prerequisite for base-level system components. This will likely encourage other distributions to evaluate their own toolchains and accelerate their adoption of Rust-based alternatives.
2. Sustained Investment in Open Source
Canonical’s involvement goes beyond mere adoption. By becoming a Gold Sponsor of the Trifecta Tech Foundation—a body dedicated to funding memory-safe system software—with a yearly commitment of €40,000, they are ensuring that the projects they rely on have the resources to remain robust and secure.
3. The Future: Beyond Coreutils
The "oxidation" of Ubuntu is far from over. The next major target is ntpd-rs, a Rust-based rewrite of the Network Time Protocol daemon. Currently in testing, this tool is slated to become the default in Ubuntu 27.04. This transition will further secure a critical piece of infrastructure—time synchronization—which is essential for system logs, security certificates, and network coordination.
4. Cultural Shift
The transition represents a cultural shift in Linux development. For decades, the C programming language was the undisputed king of systems programming. While C remains vital, the success of this project proves that a large, complex, and legacy-heavy ecosystem can successfully migrate to a modern, safer language without breaking the user experience.
Conclusion: A Measured Evolution
The journey to replace GNU Core Utilities with Rust-based equivalents is a testament to the power of methodical, well-funded open-source engineering. By pausing for audits, addressing security vulnerabilities head-on, and providing paths for legacy compatibility, Canonical has managed to perform a "heart transplant" on the Ubuntu operating system while the patient was still running.

As we move toward the next stages of this vision, the lessons learned from the uutils migration will serve as a blueprint for other distributions and projects. The goal of a more secure, memory-safe Linux ecosystem is no longer a distant theoretical ambition; thanks to the work done on Ubuntu 26.10, it is now the standard reality for millions of users worldwide.
The "oxidation" of Ubuntu is not a finish line, but a new foundation. With the core utilities now secured, the development community is better positioned than ever to tackle the next generation of security challenges in the Linux kernel and beyond.
