Skip to content

F-4.3: Device Node Creation via MKNOD

Classification

  • Severity: High
  • CVSS Vector: Network / Low Complexity / Requires Write Access
  • Affected Versions: NFSv3 (MKNOD procedure)
  • RFC Reference: RFC 1813 §3.3.11
  • Prerequisite: Writable export with no_root_squash, client mounts without nodev

Summary

The NFSv3 MKNOD procedure allows creation of block and character device nodes with arbitrary major/minor numbers. An attacker with write access (as uid=0, requiring no_root_squash) can create device nodes that map to the server's raw disk devices. When executed on a client that mounts without nodev, these device nodes provide raw disk access — bypassing all filesystem-level permissions.

Technical detail

MKNOD procedure

Per RFC 1813 §3.3.11:

"Creates a special file of the type, specdata, and attributes specified."

The call accepts: - type: NF3CHR (character device) or NF3BLK (block device) - specdata: major and minor device numbers

Attack chain

1. Attacker creates block device node on NFS export:
   MKNOD /export/.raw_disk NF3BLK major=8 minor=0  (≈ /dev/sda)
   SETATTR mode=0666  (world-readable)

2. Victim client mounts export without nodev
3. On victim: dd if=/export/.raw_disk bs=512 count=1
   → Reads raw disk sector from the NFS SERVER's /dev/sda

Common device major/minor numbers

Device Major Minor Description
/dev/sda 8 0 First SCSI/SATA disk
/dev/sdb 8 16 Second disk
/dev/nvme0n1 259 0 First NVMe disk
/dev/mem 1 1 Physical memory
/dev/kmem 1 2 Kernel memory

Raw disk exploitation

With raw disk access, an attacker can: - Read /etc/shadow directly from disk blocks (bypassing file permissions) - Read encryption keys from memory devices - Modify filesystem structures directly - Extract deleted files from unallocated blocks

Impact

  • Raw disk access bypasses all file-level permissions
  • Physical memory access possible via character device nodes
  • All data on the server's disks is potentially exposed
  • Requires both writable NFS export (no_root_squash) and client without nodev

Detection (nfswolf)

The scanner should: 1. Attempt MKNOD with NF3BLK type on writable exports 2. Check if MKNOD succeeds (indicates no_root_squash + no nodev) 3. Clean up test device nodes after detection

Remediation

  1. Mount with nodev on all NFS clients — prevents device node usage
  2. Enable root_squash (default) — prevents creating root-owned device nodes
  3. Use all_squash for maximum restriction
  4. Server-side: Mount export filesystem with nodev to prevent device node creation