From 12eb1f5d745df5dd7116944535d201c0e577fdd9 Mon Sep 17 00:00:00 2001 From: Andreas Kling Date: Sat, 4 Jan 2020 12:44:27 +0100 Subject: [PATCH] Kernel: Entries in /dev/pts should be accessible only to the owner This fixes an issue where anyone could snoop on any pseudoterminal. --- Kernel/FileSystem/DevPtsFS.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Kernel/FileSystem/DevPtsFS.cpp b/Kernel/FileSystem/DevPtsFS.cpp index 5a107a1c44..b6b23b87fc 100644 --- a/Kernel/FileSystem/DevPtsFS.cpp +++ b/Kernel/FileSystem/DevPtsFS.cpp @@ -77,7 +77,7 @@ RefPtr DevPtsFS::get_inode(InodeIdentifier inode_id) const inode->m_metadata.size = 0; inode->m_metadata.uid = device->uid(); inode->m_metadata.gid = device->gid(); - inode->m_metadata.mode = 0020644; + inode->m_metadata.mode = 0020600; inode->m_metadata.major_device = device->major(); inode->m_metadata.minor_device = device->minor(); inode->m_metadata.mtime = mepoch;