F-1.2: Root Squash Bypass via Non-Root UID¶
Classification¶
- Severity: High
- CVSS Vector: Network / Low Complexity / No Auth Required
- Affected Versions: NFSv2, NFSv3, NFSv4 with AUTH_SYS
- RFC Reference: RFC 1813 §4.4, RFC 2623 §2.5
- Prerequisite: root_squash enabled (default), target files owned by non-root users
Summary¶
Root squash is the default NFS defense: it maps UID 0 to nobody (65534). However, this ONLY protects UID 0. All non-root UIDs (1–65533) are trusted exactly as the client reports them. Since an attacker can claim any UID in their AUTH_SYS credential, root_squash provides virtually no protection — it stops exactly one out of 65,534 possible UIDs.
Technical detail¶
What root_squash actually does¶
Per RFC 1813 §4.4:
"This superuser permission may not be allowed on the server, since anyone who can become superuser on their client could gain access to all remote files."
The implementation maps uid=0 → uid=65534 (nobody). Nothing else changes.
What root_squash does NOT do¶
- Does NOT prevent spoofing uid=1000 (alice)
- Does NOT prevent spoofing uid=33 (www-data)
- Does NOT prevent spoofing uid=99 (nobody-adjacent)
- Does NOT validate that the claiming machine has the user in its passwd database
The owner bypass¶
RFC 1813 §4.4:
"The server's permission checking algorithm should allow the owner of a file to access it regardless of the permission setting."
An attacker who claims uid=<file_owner> gets full access regardless of the file's permission bits. Combined with READDIRPLUS (which reveals all file owners), an attacker can automatically impersonate each file's owner.
Exploitation¶
# List files and their owners via READDIRPLUS
nfswolf shell target:/export
nfs> ls -la
# drwx------ alice:alice .ssh/
# -rw------- bob:bob secrets.txt
# Spoof as alice (uid=1001)
nfs> uid 1001
nfs> cat .ssh/id_rsa
# Spoof as bob (uid=1002)
nfs> uid 1002
nfs> cat secrets.txt
Impact¶
- Full read/write access to any non-root-owned file on the export
- root_squash provides a false sense of security
- Administrators often skip Kerberos deployment believing root_squash is sufficient
Remediation¶
- Use
all_squashto eliminate UID trust entirely - Use Kerberos (
sec=krb5) for real identity verification - Understand that root_squash is not a security boundary — it stops the most obvious attack only