- Sources: primary, discussion
- Summary: Cloudflare reports that a Workers Paid account could read residual disk blocks left behind by other customers' Containers, including directory structures, database pages, and structurally complete SQLite databases, because the dm-thin pool ran with
skip_block_zeroing and handed reused 64 KiB blocks to a new tenant unzeroed. Cloudflare reviewed retained disk-I/O telemetry against detection signatures built from the proof of concept and attributed every match to the researchers and its own engineers, finding no other exploitation. Beyond the configuration change it retired all running container disks and cleared each host's cached dm-thin image snapshots fleet-wide, because zeroing new allocations does not sanitize mappings already present, and Cloudflare Sandboxes, which is built on Containers, was in scope. Cloudflare bounds the technique: it could not be aimed at a particular customer, workload, host or data, it could not reach an actively attached disk, and residual data was not guaranteed to be present in a reused block. - Why it matters: Block reuse without zeroing breaks the isolation that every multi-tenant container platform sells, and the exposed material was complete enough to read as databases rather than as fragments.
- Follow-up: Track whether Cloudflare publishes the exposure window and any customer notification scope.
send feedback on this story