Skip to content

F-1.2: Root Squash Bypass via Non-Root UID

Classification

  • Severity: High
  • CVSS Vector: Network / Low Complexity / No Auth Required
  • Affected Versions: NFSv2, NFSv3, NFSv4 with AUTH_SYS
  • RFC Reference: RFC 1813 §4.4, RFC 2623 §2.5
  • Prerequisite: root_squash enabled (default), target files owned by non-root users

Summary

Root squash is the default NFS defense: it maps UID 0 to nobody (65534). However, this ONLY protects UID 0. All non-root UIDs (1–65533) are trusted exactly as the client reports them. Since an attacker can claim any UID in their AUTH_SYS credential, root_squash provides virtually no protection — it stops exactly one out of 65,534 possible UIDs.

Technical detail

What root_squash actually does

Per RFC 1813 §4.4:

"This superuser permission may not be allowed on the server, since anyone who can become superuser on their client could gain access to all remote files."

The implementation maps uid=0 → uid=65534 (nobody). Nothing else changes.

What root_squash does NOT do

  • Does NOT prevent spoofing uid=1000 (alice)
  • Does NOT prevent spoofing uid=33 (www-data)
  • Does NOT prevent spoofing uid=99 (nobody-adjacent)
  • Does NOT validate that the claiming machine has the user in its passwd database

The owner bypass

RFC 1813 §4.4:

"The server's permission checking algorithm should allow the owner of a file to access it regardless of the permission setting."

An attacker who claims uid=<file_owner> gets full access regardless of the file's permission bits. Combined with READDIRPLUS (which reveals all file owners), an attacker can automatically impersonate each file's owner.

Exploitation

# List files and their owners via READDIRPLUS
nfswolf shell target:/export
nfs> ls -la
# drwx------  alice:alice   .ssh/
# -rw-------  bob:bob       secrets.txt

# Spoof as alice (uid=1001)
nfs> uid 1001
nfs> cat .ssh/id_rsa

# Spoof as bob (uid=1002)
nfs> uid 1002
nfs> cat secrets.txt

Impact

  • Full read/write access to any non-root-owned file on the export
  • root_squash provides a false sense of security
  • Administrators often skip Kerberos deployment believing root_squash is sufficient

Remediation

  1. Use all_squash to eliminate UID trust entirely
  2. Use Kerberos (sec=krb5) for real identity verification
  3. Understand that root_squash is not a security boundary — it stops the most obvious attack only