FR
live

GNOME 51 “A Coruña” drops WEP and legacy NVIDIA drivers, moves to oo7 key storage

Released September 16, 2026, GNOME 51 “A Coruña” removes WEP and legacy NVIDIA driver interfaces, migrates secret storage to the new oo7 component, and adds offline maps to Maps. For teams managing Linux fleets, this is the release to validate before it lands in major distributions.

A dark monitor on a desk, a single amber dot of light glowing at the centre of the panel.

September 16, 2026. GNOME 51, codenamed “A Coruña”, ships after six months of development, a nod to GUADEC 2026 held in that Galician city in July. WEP: the obsolete Wi-Fi standard disappears from network settings. oo7: a new component takes over key storage. Why it matters: behind a “polished” desktop release, this version carries several security decisions that will reach enterprise Linux fleets in the weeks ahead.

The end of WEP and legacy NVIDIA drivers

Two substantive removals define this release, and both are matters of security hygiene. The first is symbolic but concrete: GNOME 51 drops WEP support from Network settings. Nobody serious used it anymore, but keeping it meant continuing to offer an option that automated attack tooling can crack in minutes. Removing it aligns the desktop with modern practice — WPA2/WPA3 only.

The second removal is less visible but more structural: Mutter, GNOME’s compositor, drops legacy NVIDIA driver interfaces and now uses only the modern, standard graphics interfaces. It is a code-simplification decision that benefits current drivers, but it has an operational consequence: configurations that still rely on very old NVIDIA drivers will have to migrate before upgrading. For a fleet administrator, that is the thing to check up front — not after pushing the update across a desktop estate.

oo7 replaces the secrets keyring

The deepest change happens under the hood. GNOME now stores and retrieves passwords and keys through oo7, a new component the project describes as delivering enhanced security compared with the historical keyring mechanism. It is a quiet migration — the user sees nothing change — but it touches the core of the desktop’s trust chain: everything that passes through the secrets manager (Wi-Fi credentials, application tokens, keys) changes its underlying layer.

For a CISO or SRE standardising Linux workstations, the lesson is twofold. On one hand, a migration of this kind deserves testing on a pilot machine before a wide rollout, because it can interact with enterprise secrets tooling. On the other, it is a reminder that secret storage is not a frozen asset: it evolves with the desktop, and workstation encryption policies must keep pace.

What oo7 replaces, and why it matters

To grasp the scale of the change, it helps to know what oo7 replaces. Historically, GNOME’s secret storage ran through libsecret and the gnome-keyring daemon: a proven architecture that has aged over time, with an exposure surface that kept growing. oo7 is a rebuild of the same perimeter — the secrets manager — designed for a more modern foundation without asking anything of the user: applications keep reading secrets through the usual API, and the switch is transparent.

That is exactly what makes it both quiet and consequential. Everything that flows through the keyring — Wi-Fi credentials, online accounts, application tokens, keys — changes its underlying layer without anyone seeing it. For a CISO or SRE standardising workstations, the reflex is the same as for any critical-component migration: test on a pilot machine before rolling wide, and check that enterprise secrets tooling keeps working. An invisible switch does not mean a risk-free one — it only means that any risk will show up somewhere other than on screen.

Performance and settings that matter

The “polish” is not cosmetic. Mutter reworked its frame scheduling and screen frame delivery so animations stay smooth even under load. Screen capture is faster, thanks to the removal of redundant work and buffer copies. And GNOME now remembers monitor brightness across reboots and HDR toggles — a small fix that avoids the surprise of a reset screen on first boot.

Settings gains long-awaited features. Auto Rotate flips the screen automatically on devices with an accelerometer, with a matching orientation lock. A mouse can now disable the touchpad the moment it is plugged in — a change that transforms laptop ergonomics. Under Network, new DNS search domain settings appear, and Remote Login now accepts SSH socket servers alongside the traditional service-based setup — useful flexibility for administrators who manage desktops remotely.

Offline Maps and the rest of the batch

The most visible feature is offline maps in Maps: you can download a region and use it without a connection, a genuine win for travel abroad or patchy coverage. Transit itineraries gain live departures, real-time delays, platform indicators and walking times to stops.

The rest of the release confirms the trend: Files shows a file-count badge during drag-and-drop and clarifies read-only states; the Web browser learns to generate passwords through the pwquality library; Software now warns before installing an end-of-life application and surfaces Flatpak permissions more clearly. Add the File Previewer (Sushi) rewrite in GTK 4/libadwaita, visual signatures in Papers, and new wallpapers — the whole thing draws a desktop that consolidates rather than revolutionises.

The enterprise angle

For a fleet administrator, GNOME 51’s headline features matter less than its removals and migrations. The WEP removal and the drop of legacy NVIDIA driver interfaces are the two that will show up first in a rollout: the first is a welcome cleanup, the second a compatibility checkpoint that must be cleared before a fleet-wide upgrade. Both are the kind of change that breaks nothing on a healthy, current estate and everything on one that has been coasting.

The Software store’s end-of-life warning and the expanded Flatpak permission list carry the same message in a softer form: the desktop is quietly shifting security left, from reacting to a vulnerable package to warning before it is installed. For an organisation that standardises GNOME, these are the release notes worth reading line by line — not for what they add, but for what they will quietly stop supporting.

None of this is urgent in the way a CVE is urgent. GNOME 51 will arrive through distribution channels over the coming weeks, and the risk it carries is not exploitation but regression — a legacy driver that no longer renders, a secrets tool that no longer binds. The correct response is therefore not speed but validation: run it on a pilot machine, confirm the drivers and the secrets manager behave, and only then let the update reach the fleet. A desktop release is the rare security event where the safe move is to be methodical rather than fast.

That said, the oo7 migration deserves a closer look than the average desktop change. Secrets managers sit under every authentication flow on the machine, and a subtle incompatibility there — with an enterprise SSO agent, a VPN client, or a credential helper — will not announce itself at login; it will surface as a broken login somewhere down the line. Testing oo7 on a pilot machine before fleet rollout is not caution for caution’s sake; it is the one place where a desktop upgrade can actually take a workstation offline.

Verdict

GNOME 51 “A Coruña” is a consolidation release: few visible breaks, but removals and migrations that commit the road ahead. If you administer an enterprise Linux fleet, the watch-point is not the new features but compatibility: check the NVIDIA drivers on your machines before letting the release arrive through updates, and test oo7 on a pilot machine if you manage enterprise secrets. If you run a single desktop, the upgrade is uneventful — offline maps, better performance and settings, nothing to lose. If you track your distribution’s cycle, the version will arrive “in the coming weeks” through the usual channels; now is the time to read the release notes rather than skip them.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

A length miscalculation in Linux IPv6 fragmentation enables container escape

Red Hat has published a bulletin for CVE-2026-53362, an out-of-bounds write in the Linux kernel’s IPv6 fragmentation path that lets a local user escape a container and bypass SELinux. Apply the patched kernel, or disable unprivileged user namespaces in the meantime.

← Back to the feed

Type at least two characters.

navigate open esc dismiss