F-4.6: Unrestricted chown (Any User Can Change File Ownership)¶
Classification¶
- Severity: High
- CVSS Vector: Network / Low Complexity / Auth Required (any UID)
- Affected Versions: NFSv2, NFSv3
- RFC Reference: RFC 1094 S3.3 (SETATTR semantics), RFC 1813 S4.4 (PATHCONF)
- Prerequisite: Write access to at least one file on the export; server returns chown_restricted=false
Summary¶
When PATHCONF reports chown_restricted=false for an export, any user who owns a file can change its uid and gid to arbitrary values via SETATTR. This breaks the fundamental Unix assumption that only root can give files away. An attacker can create a file, chown it to root, set the SUID bit, and execute it on any client that mounts the export without nosuid, achieving full root compromise without ever needing root credentials on the NFS server.
Technical detail¶
PATHCONF chown_restricted field¶
RFC 1813 S3.3.20 defines PATHCONF as returning filesystem properties per export. The chown_restricted field maps to _POSIX_CHOWN_RESTRICTED:
- true (normal): Only root can change file ownership. Non-root users can only chgrp to groups they belong to.
- false (dangerous): Any file owner can SETATTR the uid/gid fields to any value.
Attack chain¶
1. Attacker connects as uid=1000 (any unprivileged user)
2. CREATE a new file -> attacker owns it
3. SETATTR uid=0, gid=0 -> file now owned by root (allowed because chown_restricted=false)
4. WRITE a SUID shell binary into the file
5. SETATTR mode=04755 -> SUID root
6. On any client mounting without nosuid: execute the binary -> root shell
Where this occurs¶
| Platform | chown_restricted | Notes |
|---|---|---|
| Linux ext4/XFS/btrfs | true (default) | POSIX compliant |
| Solaris UFS | Configurable | rstchown tuneable in /etc/system |
| HP-UX | Configurable | setprivgrp controls group ownership |
| AIX JFS/JFS2 | Configurable | chown_restricted mount option |
| FreeBSD UFS | true (default) | sysctl kern.chown_restricted |
| Windows NFS (NTFS) | false | NTFS has its own ACL model; POSIX semantics don't map cleanly |
| Legacy NAS appliances | Varies | Often misconfigured |
SUID binary payload¶
/* Minimal setuid root shell */
#include <unistd.h>
int main(void) {
setuid(0);
setgid(0);
execl("/bin/sh", "sh", NULL);
}
With unrestricted chown, no no_root_squash is needed. The attacker changes ownership after creating the file as a regular user.
Impact¶
- Root compromise on all clients mounting the export without
nosuid - No root credentials required -- any unprivileged user with write access can escalate
- Bypasses root_squash -- the attack never uses uid=0 for the initial write, only for the chown
- Persistence -- SUID binaries survive reboots and are hard to distinguish from legitimate files
Detection (nfswolf)¶
The analyzer calls PATHCONF on each export root handle and checks the chown_restricted field. If the server returns false, the finding fires at High severity. The check requires a valid file handle from a successful MNT call.
For NFSv2, PATHCONF is not available as a wire procedure. The analyzer falls back to attempting a SETATTR uid change on a test file when --allow-write is enabled; without write permission, the v2 check is skipped with a note.
Remediation¶
-
Enable
_POSIX_CHOWN_RESTRICTEDon the exported filesystem: -
Mount with
nosuid,nodevon all NFS clients (defense in depth even if chown is restricted): -
Use
all_squashon the server export, which maps all UIDs toanonuidand prevents ownership manipulation entirely -
Monitor for SUID creation -- audit SETATTR calls that set the SUID bit on NFS exports