Skip to content

F-7.3: nohide/crossmnt Sub-Mount Exposure

Classification

  • Severity: Medium
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: NFSv3 and NFSv4 on Linux
  • RFC Reference: RFC 1813 §3.3.3, §4.2
  • Prerequisite: Export configured with nohide or crossmnt options

Summary

By default, NFS servers do not allow LOOKUP operations to cross filesystem mount points within an export. The nohide and crossmnt export options override this restriction, transparently exposing sub-mounted filesystems to NFS clients. If a parent export uses crossmnt, ALL filesystems mounted underneath it become accessible — even if they contain more sensitive data than the parent export intended to share.

Technical detail

Default behavior

Per RFC 1813 §3.3.3:

"A server will not allow a LOOKUP operation to cross a mountpoint."

This means if /srv/data is exported and /srv/data/secrets is a separate filesystem mounted inside it, NFS clients cannot see or access /srv/data/secrets — the mount boundary acts as a wall.

What nohide/crossmnt do

  • nohide (per-export): Makes a child export visible through the parent export, even if on a different filesystem
  • crossmnt (per-export): Like nohide but applies recursively — ALL sub-mounts become visible
# /etc/exports
/srv/data       *(rw,crossmnt)

With this configuration, if the server has:

/srv/data                  (exported, ext4 on /dev/sda2)
/srv/data/logs             (mounted, ext4 on /dev/sda3)
/srv/data/backups          (mounted, xfs on /dev/sdb1)
/srv/data/secrets          (mounted, ext4 on /dev/sdc1)

ALL of /srv/data/logs, /srv/data/backups, and /srv/data/secrets are accessible via the single /srv/data export — even though they're separate filesystems that weren't individually exported.

Common misconfiguration

Administrators often use crossmnt on a root-level export for convenience:

/  *(ro,fsid=0,crossmnt)    # NFSv4 pseudo-root with crossmnt

This exposes every mounted filesystem on the server to NFS clients.

Interaction with subtree_check

When crossmnt exposes a sub-mount, the export escape protections of subtree_check become irrelevant — the server willingly serves files across filesystem boundaries.

Impact

  • Filesystems not intended for NFS export become accessible
  • Backup volumes, log volumes, and other sensitive data exposed
  • Breaks the administrator's assumption about what's shared
  • Combined with UID spoofing, all files on all sub-mounts are accessible

Detection (nfswolf)

The scanner should: 1. Mount an export and attempt LOOKUP/READDIRPLUS across apparent mount boundaries 2. Compare device IDs (from GETATTR) of parent and child directories 3. If device IDs differ, a filesystem boundary was crossed — report nohide/crossmnt 4. Map all accessible sub-mounts from a single export

Remediation

  1. Avoid crossmnt and nohide unless explicitly required
  2. Export each filesystem separately with its own ACL
  3. If crossmnt is needed, ensure all sub-mounts are intended to be shared
  4. Audit sub-mounts: findmnt --submounts /srv/data to see what crossmnt exposes
  5. Use separate filesystem boundaries as security boundaries — don't rely on NFS to enforce them when crossmnt is set