Skip to content

F-5.11: Filesystem Lacks Link/Symlink Support (Reduced Attack Surface)

Classification

  • Severity: Info
  • CVSS Vector: Network / Low Complexity / Low Privileges Required
  • Affected Versions: NFSv3 (via FSINFO)
  • RFC Reference: RFC 1813 S3.3.20 (FSINFO properties bitmask)
  • Prerequisite: Valid file handle for the export root

Summary

The FSINFO procedure (RFC 1813 S3.3.20) returns a properties bitmask that reports whether the underlying filesystem supports hard links (FSF3_LINK, bit 0x0001) and symbolic links (FSF3_SYMLINK, bit 0x0002). When either bit is absent, the corresponding class of attacks is structurally impossible on that export. Symlink escape (F-4.4) requires symlink support; hardlink-based attacks require FSF3_LINK. This is an informational signal that narrows the effective attack surface during automated analysis.

Technical detail

FSINFO properties bitmask

RFC 1813 S3.3.20 defines:

FSF3_LINK       = 0x0001   /* server supports hard links */
FSF3_SYMLINK    = 0x0002   /* server supports symbolic links */
FSF3_HOMOGENEOUS = 0x0008  /* PATHCONF results are the same for all files */
FSF3_CANSETTIME  = 0x0010  /* server can set times on files */

Filesystem support matrix

Filesystem FSF3_LINK FSF3_SYMLINK Notes
ext4 / XFS / btrfs Yes Yes Full POSIX
VFAT No No No POSIX semantics
ISO9660 (cdrom) No Partial Rock Ridge extensions may add symlinks
SquashFS Yes Yes Read-only, but reports support
NTFS3 Yes Partial NTFS symlinks differ from POSIX
UDF No Yes Depends on UDF revision

Attack surface reduction

When FSF3_LINK is absent: - Hard link attacks cannot be used to create alternate names for sensitive files - The LINK procedure (RFC 1813 S3.3.15) will fail with NFS3ERR_NOTSUPP

When FSF3_SYMLINK is absent: - Symlink escape (F-4.4) is inapplicable -- SYMLINK returns NFS3ERR_NOTSUPP - Symlink race conditions targeting local processes are not possible via NFS

Impact

  • Informational only -- this is a positive indicator that reduces the attack surface
  • Guides automated tooling to skip inapplicable checks, reducing noise and scan time
  • A filesystem lacking both link types is likely non-POSIX (VFAT, ISO9660) and may have other unusual characteristics relevant to escape analysis

Detection (nfswolf)

The analyzer calls FSINFO on each export root handle and checks the FSF3_LINK (0x0001) and FSF3_SYMLINK (0x0002) bits in the properties field. If either bit is absent, the finding fires at Info severity, listing which capabilities are missing.

Remediation

No action required. This finding is informational -- the filesystem type is a deployment choice, and the absence of link/symlink support is a security benefit in this context.