Executive brief
A vulnerability in certain Network File System (NFS) implementations allows local users to bypass security controls and gain full administrative control over the system. By creating a specialized device file, an attacker can gain direct access to system memory, leading to a complete compromise of data confidentiality and system integrity. This could result in unauthorized access to sensitive information or the ability to disrupt critical operations.
Technical details
This vulnerability is a privilege escalation flaw resulting from improper management of the mknod operation in certain NFS server implementations. A local attacker can use the mknod command to create a character special file that maps to kernel memory (/dev/kmem). By setting the ownership of this device to UID 0 (root) and ensuring it is writable, the attacker can directly modify kernel memory to escalate their privileges to root. The attack requires local access to an NFS-mounted filesystem that does not properly restrict the creation of device nodes. This issue is categorized under CWE-269 (Improper Privilege Management).
Affected products
- Generic NFS Server
Timeline
- 1990-05-01: disclosed