Cloudflare fixes cross-tenant data exposure in Containers
Cloudflare disclosed a cross-tenant data exposure flaw in Containers: a Workers Paid customer could read residual disk blocks left by other customers' containers on the same host. The cause was skip_block_zeroing in dm-thin with a 64 KiB block size. It has been remediated with no evidence of exploitation.
- Flaw was in the dm-thin allocator, not the Firecracker VM boundary
- A 4 KiB write allocated a 64 KiB block, leaving up to 60 KiB of foreign data
- All 5,614 testable directory blocks came from other tenants
- Fix landed Sept 4; full cleanup finished Sept 19
Read next
Security