Skip to content

F-7.4: Missing nosuid/nodev on Client Mount

Classification

  • Severity: High
  • CVSS Vector: Local / Low Complexity / Requires Client Access
  • Affected Versions: All NFS versions
  • RFC Reference: RFC 1094 §2.3.5 (SUID bits in mode), RFC 1813 §3.3.11 (MKNOD)
  • Prerequisite: NFS client mounts without nosuid and/or nodev options

Summary

When NFS clients mount exports without the nosuid and nodev options, SUID/SGID binaries and device nodes on the NFS share are honored by the client kernel. An attacker who can write to the NFS export (from any machine) can plant SUID root binaries or device nodes that escalate privileges when used on the vulnerable client. This is a client-side misconfiguration that makes exploitation of write-access findings (F-4.1, F-4.2, F-4.3) dramatically more impactful.

Technical detail

Default mount behavior

Most Linux distributions mount NFS without nosuid or nodev by default. The kernel therefore: - Honors SUID/SGID bits on NFS-served executables - Honors block/character device nodes on NFS-served filesystems

The privilege escalation chain

1. Attacker writes SUID root binary to NFS export (see F-4.2)
2. Client mounts export without nosuid
3. Any user on client executes the binary
4. Kernel sets uid=0 (SUID bit honored)
5. Root shell on client

Checking client mount options

# Vulnerable (no nosuid/nodev):
target:/export on /mnt type nfs (rw,vers=3)

# Secure:
target:/export on /mnt type nfs (rw,nosuid,nodev,noexec,vers=3)

fstab Configuration

# Vulnerable:
target:/export  /mnt  nfs  defaults  0 0

# Secure:
target:/export  /mnt  nfs  nosuid,nodev,noexec,nolock  0 0

Impact

  • SUID binaries on NFS shares execute with elevated privileges on the client
  • Device nodes on NFS shares provide raw device access from the client
  • Every client mounting without nosuid/nodev is a potential privilege escalation target
  • Server-side attacks (write SUID binary) become client-side root

Detection (nfswolf)

The scanner should: 1. Report when SUID/SGID files are found on exports (via GETATTR mode bits) 2. Report when device nodes are found on exports 3. Note that impact depends on client-side mount options (not server-observable)

Remediation

  1. Always mount NFS with nosuid,nodev,noexec:
    target:/export  /mnt  nfs  nosuid,nodev,noexec  0 0
    
  2. Audit existing mounts: mount | grep nfs | grep -v nosuid
  3. Server-side: Mount export filesystems with nosuid,nodev to prevent SUID creation
  4. Use root_squash (default) to prevent root-owned SUID creation
  5. File integrity monitoring on NFS mounts for SUID file changes