F-7.4: Missing nosuid/nodev on Client Mount¶
Classification¶
- Severity: High
- CVSS Vector: Local / Low Complexity / Requires Client Access
- Affected Versions: All NFS versions
- RFC Reference: RFC 1094 §2.3.5 (SUID bits in mode), RFC 1813 §3.3.11 (MKNOD)
- Prerequisite: NFS client mounts without nosuid and/or nodev options
Summary¶
When NFS clients mount exports without the nosuid and nodev options, SUID/SGID binaries and device nodes on the NFS share are honored by the client kernel. An attacker who can write to the NFS export (from any machine) can plant SUID root binaries or device nodes that escalate privileges when used on the vulnerable client. This is a client-side misconfiguration that makes exploitation of write-access findings (F-4.1, F-4.2, F-4.3) dramatically more impactful.
Technical detail¶
Default mount behavior¶
Most Linux distributions mount NFS without nosuid or nodev by default. The kernel therefore:
- Honors SUID/SGID bits on NFS-served executables
- Honors block/character device nodes on NFS-served filesystems
The privilege escalation chain¶
1. Attacker writes SUID root binary to NFS export (see F-4.2)
2. Client mounts export without nosuid
3. Any user on client executes the binary
4. Kernel sets uid=0 (SUID bit honored)
5. Root shell on client
Checking client mount options¶
# Vulnerable (no nosuid/nodev):
target:/export on /mnt type nfs (rw,vers=3)
# Secure:
target:/export on /mnt type nfs (rw,nosuid,nodev,noexec,vers=3)
fstab Configuration¶
# Vulnerable:
target:/export /mnt nfs defaults 0 0
# Secure:
target:/export /mnt nfs nosuid,nodev,noexec,nolock 0 0
Impact¶
- SUID binaries on NFS shares execute with elevated privileges on the client
- Device nodes on NFS shares provide raw device access from the client
- Every client mounting without nosuid/nodev is a potential privilege escalation target
- Server-side attacks (write SUID binary) become client-side root
Detection (nfswolf)¶
The scanner should: 1. Report when SUID/SGID files are found on exports (via GETATTR mode bits) 2. Report when device nodes are found on exports 3. Note that impact depends on client-side mount options (not server-observable)
Remediation¶
- Always mount NFS with
nosuid,nodev,noexec: - Audit existing mounts:
mount | grep nfs | grep -v nosuid - Server-side: Mount export filesystems with
nosuid,nodevto prevent SUID creation - Use
root_squash(default) to prevent root-owned SUID creation - File integrity monitoring on NFS mounts for SUID file changes