Skip to content

F-5.14: POSIX ACL Entries Expose Access Beyond Mode Bits

Classification

  • Severity: Medium (Information Disclosure / Credential Discovery)
  • CVSS Vector: Network / Low Complexity / Low Privileges Required
  • Affected Versions: NFSv2, NFSv3 (via NFS_ACL sideband protocol)
  • Service: NFS_ACL (program 100227, version 3, procedure GETACL)
  • Prerequisite: NFS_ACL program reachable (typically same port as NFS, 2049)

Summary

The NFS_ACL sideband protocol (program 100227) exposes POSIX ACL entries that grant access to specific UIDs and GIDs invisible to standard mode-bit analysis. When GETACL returns named USER or GROUP ACL entries on the export root, it reveals UIDs and GIDs with access paths that ls -l does not show. These identities feed the credential ladder for targeted escalation: an attacker learns exactly which UIDs have access before attempting to spoof them, skipping blind brute-force entirely.

Technical detail

NFS_ACL protocol

The NFS_ACL protocol is a de facto standard originating from Solaris (nfsacl_prot.x), with no formal RFC. Linux knfsd hosts it on the same port as NFS (2049) as a separate RPC program. The protocol mirrors POSIX ACL semantics over the wire.

GETACL3 (procedure 1):
  Input:  file_handle + mask (NFS_ACL=0x01, NFS_DFACL=0x04)
  Output: status + fattr3 + access_acl[] + default_acl[]

Each ACL entry is a 12-byte structure:

Field Size Values
a_type 4 bytes USER_OBJ (0x01), USER (0x02), GROUP_OBJ (0x04), GROUP (0x08), MASK (0x10), OTHER (0x20)
a_id 4 bytes UID or GID (meaningful for USER and GROUP types)
a_perm 4 bytes rwx bitmask (4=r, 2=w, 1=x)

What mode bits miss

Standard mode bits encode three permission triples: owner, group, other. POSIX ACLs extend this with per-identity grants:

# Mode bits show:    drwxr-x---  root:staff
# POSIX ACLs reveal:
user::rwx          # USER_OBJ (same as mode owner bits)
user:deploy:rwx    # USER -- uid 1001 has full access
user:backup:r-x    # USER -- uid 1002 has read/traverse
group::r-x         # GROUP_OBJ (same as mode group bits)
group:dev:rwx      # GROUP -- gid 2001 has full access
mask::rwx          # MASK -- effective permissions cap
other::---         # OTHER (same as mode other bits)

In this example, ls -l shows only root:staff ownership. The attacker has no way to discover UIDs 1001, 1002, or GID 2001 from mode bits alone. GETACL exposes all of them.

Credential ladder integration

Named ACL entries provide high-value credential targets because:

  1. Confirmed access: The UID/GID is explicitly granted access, so no guessing is required
  2. Permission level known: The a_perm field reveals whether the identity has read, write, or execute access
  3. Invisible to other checks: Neither READDIRPLUS ownership scanning nor FSSTAT will reveal these identities
  4. Default ACLs predict child access: Default ACL entries (NFS_DFACL) reveal identities that will have access to any new files created in the directory

Default ACLs

Default ACLs (mask = NFS_DFACL, 0x04) are inherited by new files and subdirectories. They reveal the intended access policy for future content, which may include service accounts, deployment users, or monitoring agents that have not yet created files.

Exploitation

Automated (nfswolf)

# The analyzer probes NFS_ACL during analysis:
nfswolf analyze target:/export

# Output when named ACL entries are found:
# [MEDIUM] F-5.14: POSIX ACL entries expose access beyond mode bits
#   Evidence: NFS_ACL GETACL returned 3 named entries on export root:
#     uid=1001 rwx, gid=2001 rwx, default:user=1002 r-x

Manual

# Using nfs-utils getfacl over a mounted export:
mount -t nfs target:/export /mnt
getfacl /mnt
# user::rwx
# user:deploy:rwx
# user:backup:r-x
# group::r-x
# group:dev:rwx
# mask::rwx
# other::---

# Using nfswolf shell to read ACLs without mounting:
nfswolf shell target:/export
> acl .

Impact

  • Credential discovery: UIDs and GIDs with explicit access grants are revealed, bypassing the need for UID brute-force
  • Access path analysis: Named ACL entries show the exact permission level for each identity, enabling targeted exploitation
  • Hidden access exposure: Access grants invisible to ls -l and standard READDIRPLUS analysis are disclosed
  • Credential ladder acceleration: Discovered UIDs/GIDs are high-confidence targets for AUTH_SYS credential spoofing (F-1.1)

Limitations

  • The NFS_ACL program is not universally available; NetApp ONTAP, FreeBSD, and some Solaris versions may not support it or may restrict access
  • Linux knfsd hosts NFS_ACL on the NFS port (2049), so firewalling it separately from NFS is not possible
  • ACL entries only appear on files that have explicit ACLs set; the majority of files use only standard mode bits

Detection (nfswolf)

The analyzer connects to the NFS_ACL program (100227 v3) on the NFS port and issues GETACL with mask = NFS_ACL | NFS_DFACL (0x05) against the export root handle. If the response contains USER (0x02) or GROUP (0x08) type entries in either the access or default ACL arrays, the finding fires at Medium severity. The evidence lists each named entry with its UID/GID and permission string.

Remediation

  1. Review POSIX ACLs on exports -- audit named ACL entries and remove unnecessary grants:

    getfacl -R /export | grep -E '^(user|group):[^:]+:'
    setfacl -b /export  # remove all ACLs (reverts to mode bits only)
    

  2. Restrict NFS_ACL access -- Linux knfsd does not support disabling NFS_ACL independently of NFS. The only mitigation is ensuring ACL entries do not expose sensitive identities.

  3. Use Kerberos -- sec=krb5 prevents credential spoofing, so even if UIDs are discovered via ACLs, the attacker cannot impersonate them without a valid Kerberos ticket

  4. Prefer NFSv4 ACLs -- NFSv4 rich ACLs (system.nfs4_acl) are accessed through the NFS protocol itself rather than a sideband protocol, and are subject to the export's sec= enforcement

Finding Relationship
F-1.1: UID/GID Spoofing Discovered UIDs/GIDs are spoofed via AUTH_SYS to exercise the revealed access
F-5.13: NFSv4 Named Attributes Presence of system.posix_acl_access xattr predicts this finding
F-5.2: READDIRPLUS Harvesting READDIRPLUS reveals file ownership; ACLs reveal hidden grants beyond ownership