F-4.3: Device Node Creation via MKNOD¶
Classification¶
- Severity: High
- CVSS Vector: Network / Low Complexity / Requires Write Access
- Affected Versions: NFSv3 (MKNOD procedure)
- RFC Reference: RFC 1813 §3.3.11
- Prerequisite: Writable export with no_root_squash, client mounts without
nodev
Summary¶
The NFSv3 MKNOD procedure allows creation of block and character device nodes with arbitrary major/minor numbers. An attacker with write access (as uid=0, requiring no_root_squash) can create device nodes that map to the server's raw disk devices. When executed on a client that mounts without nodev, these device nodes provide raw disk access — bypassing all filesystem-level permissions.
Technical detail¶
MKNOD procedure¶
Per RFC 1813 §3.3.11:
"Creates a special file of the type, specdata, and attributes specified."
The call accepts:
- type: NF3CHR (character device) or NF3BLK (block device)
- specdata: major and minor device numbers
Attack chain¶
1. Attacker creates block device node on NFS export:
MKNOD /export/.raw_disk NF3BLK major=8 minor=0 (≈ /dev/sda)
SETATTR mode=0666 (world-readable)
2. Victim client mounts export without nodev
3. On victim: dd if=/export/.raw_disk bs=512 count=1
→ Reads raw disk sector from the NFS SERVER's /dev/sda
Common device major/minor numbers¶
| Device | Major | Minor | Description |
|---|---|---|---|
| /dev/sda | 8 | 0 | First SCSI/SATA disk |
| /dev/sdb | 8 | 16 | Second disk |
| /dev/nvme0n1 | 259 | 0 | First NVMe disk |
| /dev/mem | 1 | 1 | Physical memory |
| /dev/kmem | 1 | 2 | Kernel memory |
Raw disk exploitation¶
With raw disk access, an attacker can:
- Read /etc/shadow directly from disk blocks (bypassing file permissions)
- Read encryption keys from memory devices
- Modify filesystem structures directly
- Extract deleted files from unallocated blocks
Impact¶
- Raw disk access bypasses all file-level permissions
- Physical memory access possible via character device nodes
- All data on the server's disks is potentially exposed
- Requires both writable NFS export (no_root_squash) and client without
nodev
Detection (nfswolf)¶
The scanner should: 1. Attempt MKNOD with NF3BLK type on writable exports 2. Check if MKNOD succeeds (indicates no_root_squash + no nodev) 3. Clean up test device nodes after detection
Remediation¶
- Mount with
nodevon all NFS clients — prevents device node usage - Enable
root_squash(default) — prevents creating root-owned device nodes - Use
all_squashfor maximum restriction - Server-side: Mount export filesystem with
nodevto prevent device node creation