INFRA Signal 275
Cloudflare remediates storage flaw that could expose tenant data from 64 KiB blocks
A Cloudflare Containers storage flaw could expose residual tenant data after 4 KiB writes reused uncleared 64 KiB blocks.
Cloudflare's fix addresses a significant storage flaw that could potentially lead to data leakage between customers. This incident highlights the importance of proper storage management and data isolation in shared environments, especially for services that handle sensitive information.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Cloudflare's fix involved removing the unsafe configuration and retiring existing container disks.
The vulnerability could allow residual data from deleted containers to be read by new tenants due to improper block zeroing.
Cloudflare found no evidence of actual data being accessed, but the potential for exposure was significant.
THE READ
What the cluster adds up to.
Cloudflare's recent remediation addresses a critical flaw in its Containers service that allowed for the potential exposure of residual data from deleted container disks. Specifically, the issue arose from the reuse of 64 KiB blocks that were not properly zeroed out after deletion, enabling new tenants to read leftover data from previous customers.
The fix included the removal of the configuration responsible for skipping block zeroing, along with the retirement of existing container disks to eliminate any potential for data leakage. This remediation was applied automatically, meaning customers did not need to make any changes to their applications or settings, which simplifies the response to the issue.
While Cloudflare's internal review found no evidence of real-world exploitation, the researchers were able to demonstrate that stale data was technically recoverable under specific test conditions. This incident emphasizes the need for robust data sanitization practices, particularly in multi-tenant environments where data isolation is critical.
The vulnerability affected customers on the Workers Paid plan and also had implications for Cloudflare Sandboxes and Browser Run services due to shared storage implementations. Understanding the scope of the flaw is essential for users relying on these services to manage sensitive data.
This event serves as a reminder for cloud service providers to continuously evaluate their data management practices. The potential for data remnants to be accessed highlights the necessity for stringent controls around data lifecycle management, especially in environments where multiple clients share the same resources.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗