Skip to content

F-4.6: Unrestricted chown (Any User Can Change File Ownership)

Classification

  • Severity: High
  • CVSS Vector: Network / Low Complexity / Auth Required (any UID)
  • Affected Versions: NFSv2, NFSv3
  • RFC Reference: RFC 1094 S3.3 (SETATTR semantics), RFC 1813 S4.4 (PATHCONF)
  • Prerequisite: Write access to at least one file on the export; server returns chown_restricted=false

Summary

When PATHCONF reports chown_restricted=false for an export, any user who owns a file can change its uid and gid to arbitrary values via SETATTR. This breaks the fundamental Unix assumption that only root can give files away. An attacker can create a file, chown it to root, set the SUID bit, and execute it on any client that mounts the export without nosuid, achieving full root compromise without ever needing root credentials on the NFS server.

Technical detail

PATHCONF chown_restricted field

RFC 1813 S3.3.20 defines PATHCONF as returning filesystem properties per export. The chown_restricted field maps to _POSIX_CHOWN_RESTRICTED:

  • true (normal): Only root can change file ownership. Non-root users can only chgrp to groups they belong to.
  • false (dangerous): Any file owner can SETATTR the uid/gid fields to any value.

Attack chain

1. Attacker connects as uid=1000 (any unprivileged user)
2. CREATE a new file -> attacker owns it
3. SETATTR uid=0, gid=0 -> file now owned by root (allowed because chown_restricted=false)
4. WRITE a SUID shell binary into the file
5. SETATTR mode=04755 -> SUID root
6. On any client mounting without nosuid: execute the binary -> root shell

Where this occurs

Platform chown_restricted Notes
Linux ext4/XFS/btrfs true (default) POSIX compliant
Solaris UFS Configurable rstchown tuneable in /etc/system
HP-UX Configurable setprivgrp controls group ownership
AIX JFS/JFS2 Configurable chown_restricted mount option
FreeBSD UFS true (default) sysctl kern.chown_restricted
Windows NFS (NTFS) false NTFS has its own ACL model; POSIX semantics don't map cleanly
Legacy NAS appliances Varies Often misconfigured

SUID binary payload

/* Minimal setuid root shell */
#include <unistd.h>
int main(void) {
    setuid(0);
    setgid(0);
    execl("/bin/sh", "sh", NULL);
}

With unrestricted chown, no no_root_squash is needed. The attacker changes ownership after creating the file as a regular user.

Impact

  • Root compromise on all clients mounting the export without nosuid
  • No root credentials required -- any unprivileged user with write access can escalate
  • Bypasses root_squash -- the attack never uses uid=0 for the initial write, only for the chown
  • Persistence -- SUID binaries survive reboots and are hard to distinguish from legitimate files

Detection (nfswolf)

The analyzer calls PATHCONF on each export root handle and checks the chown_restricted field. If the server returns false, the finding fires at High severity. The check requires a valid file handle from a successful MNT call.

For NFSv2, PATHCONF is not available as a wire procedure. The analyzer falls back to attempting a SETATTR uid change on a test file when --allow-write is enabled; without write permission, the v2 check is skipped with a note.

Remediation

  1. Enable _POSIX_CHOWN_RESTRICTED on the exported filesystem:

    # Solaris
    echo "set rstchown = 1" >> /etc/system
    # AIX
    chfs -a chown_restricted=yes /export
    

  2. Mount with nosuid,nodev on all NFS clients (defense in depth even if chown is restricted):

    server:/export  /mnt  nfs  nosuid,nodev  0 0
    

  3. Use all_squash on the server export, which maps all UIDs to anonuid and prevents ownership manipulation entirely

  4. Monitor for SUID creation -- audit SETATTR calls that set the SUID bit on NFS exports