F-7.3: nohide/crossmnt Sub-Mount Exposure¶
Classification¶
- Severity: Medium
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: NFSv3 and NFSv4 on Linux
- RFC Reference: RFC 1813 §3.3.3, §4.2
- Prerequisite: Export configured with
nohideorcrossmntoptions
Summary¶
By default, NFS servers do not allow LOOKUP operations to cross filesystem mount points within an export. The nohide and crossmnt export options override this restriction, transparently exposing sub-mounted filesystems to NFS clients. If a parent export uses crossmnt, ALL filesystems mounted underneath it become accessible — even if they contain more sensitive data than the parent export intended to share.
Technical detail¶
Default behavior¶
Per RFC 1813 §3.3.3:
"A server will not allow a LOOKUP operation to cross a mountpoint."
This means if /srv/data is exported and /srv/data/secrets is a separate filesystem mounted inside it, NFS clients cannot see or access /srv/data/secrets — the mount boundary acts as a wall.
What nohide/crossmnt do¶
nohide(per-export): Makes a child export visible through the parent export, even if on a different filesystemcrossmnt(per-export): Like nohide but applies recursively — ALL sub-mounts become visible
With this configuration, if the server has:
/srv/data (exported, ext4 on /dev/sda2)
/srv/data/logs (mounted, ext4 on /dev/sda3)
/srv/data/backups (mounted, xfs on /dev/sdb1)
/srv/data/secrets (mounted, ext4 on /dev/sdc1)
ALL of /srv/data/logs, /srv/data/backups, and /srv/data/secrets are accessible via the single /srv/data export — even though they're separate filesystems that weren't individually exported.
Common misconfiguration¶
Administrators often use crossmnt on a root-level export for convenience:
This exposes every mounted filesystem on the server to NFS clients.
Interaction with subtree_check¶
When crossmnt exposes a sub-mount, the export escape protections of subtree_check become irrelevant — the server willingly serves files across filesystem boundaries.
Impact¶
- Filesystems not intended for NFS export become accessible
- Backup volumes, log volumes, and other sensitive data exposed
- Breaks the administrator's assumption about what's shared
- Combined with UID spoofing, all files on all sub-mounts are accessible
Detection (nfswolf)¶
The scanner should:
1. Mount an export and attempt LOOKUP/READDIRPLUS across apparent mount boundaries
2. Compare device IDs (from GETATTR) of parent and child directories
3. If device IDs differ, a filesystem boundary was crossed — report nohide/crossmnt
4. Map all accessible sub-mounts from a single export
Remediation¶
- Avoid
crossmntandnohideunless explicitly required - Export each filesystem separately with its own ACL
- If
crossmntis needed, ensure all sub-mounts are intended to be shared - Audit sub-mounts:
findmnt --submounts /srv/datato see whatcrossmntexposes - Use separate filesystem boundaries as security boundaries — don't rely on NFS to enforce them when
crossmntis set