THE CRUNCH

Cloudflare has patched a storage flaw that could let a customer recover residual disk blocks from other tenants on the same host, the company says. The issue affected Cloudflare Containers and Sandboxes, which run workloads on multi-tenant infrastructure. A security researcher reported that a customer with a Workers Paid account could read previously used disk blocks if the underlying storage pool had block zeroing,

The vulnerability relied on Linux device mapper thin provisioning with a 64 KiB block size and the skip_block_zeroing option. This meant that when a container was deleted, its physical blocks were returned to a shared pool without being wiped. A proof of concept showed that writing small amounts of data to previously used blocks could leave the rest of the block readable. The researchers validated the issue by testing six production placements and found residual data on 18 of 24, including directory structures and database pages.

Cloudflare has applied a fix across the Containers fleet with no customer-side configuration changes required. The company says it has no evidence that customer data was compromised and that the researchers only recovered aggregate counts and format checks, not file contents. The researchers also confirmed that they securely deleted the recovered data, consistent with Cloudflare’s disclosure policy.

The researchers used ext4 directory block checksums to distinguish their own test filesystem from foreign data. This allowed them to identify 2,700 distinct foreign directory inodes across the test placements. The recovered block types included directory structures, database pages, and structurally complete SQLite databases, though the researchers did not recover file contents or third-party identifiers.

Cloudflare says the technique could not target a particular customer, workload, host, or data, and that residual data was not guaranteed to be present. The company also noted that it found no evidence of malicious exploitation in its historical disk-I/O telemetry, with all activity attributed to the researchers and engineers conducting validation.

WHAT HAPPENS NEXT

Cloudflare has fully remediated the vulnerability and applied the fix across the Containers fleet. The company says it has no evidence that customer data was compromised and that the researchers only recovered aggregate counts and format checks, not file contents.