Customers of Cloudflare's Containers service could read scraps of data that other customers had left on the same machine. A security researcher reported the flaw on September 4, and Cloudflare had a fix in place three days later. The company has now described what went wrong.

Cloud services run many customers on the same hardware, and each one expects to see only its own data. Here that separation broke down on the disk itself.

Space that was never wiped

Containers, and the Sandboxes built on top of it, give each container its own virtual disk carved from a shared pool of storage in blocks of 64 KiB. When a container was deleted, its blocks went back to the pool. A setting called skip_block_zeroing meant they were not wiped first.

A new container that wrote a small piece of data into a reused block changed only that piece. The rest of the block still held what the previous owner had written, and the new customer could read it. A Workers Paid account was enough, according to Cloudflare.

What the researcher found

Oren Yomtov of the company Accomplish reported the bug through HackerOne, a platform that pays for security findings. In testing, leftover data turned up on 18 of 24 container placements and on 20 of 22 underlying machines, on four continents.

The recovered material included folder structures, database pages and complete SQLite databases. According to BleepingComputer, it could also include browser profiles, configuration files and files with login credentials.

Fixed, with no sign of abuse

Cloudflare turned off the setting, retired the container disks in use and cleared cached image snapshots. It finished the cleanup across its network on September 19. The researcher received a bounty on September 14.

The company says a review of its logs found no sign that anyone besides the researcher and its own staff used the flaw. Customers do not need to do anything.