Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Cloudflare Fixes Cross-Tenant Data Exposure Bug in Containers

Дата публикации: 25-09-2026 10:46:43

Cloudflare has patched a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes, which is built on Containers. Security researcher Oren Yomtov from Accomplish reported the flaw on September 4, 2026, through Cloudflare's HackerOne bug bounty program, and Cloudflare says it has no evidence that customer data has been compromised.  How the Storage Flaw Exposed Cross-Tenant Data […]

Основное содержимое страницы с новостью.

Isolated Storage Units - Reassigned Unit - Residual Documents - Database Records - Inspection Worker

Key Takeaways

  • Reported flaw: An Accomplish researcher disclosed a Cloudflare Containers cross-tenant bug via HackerOne on September 4, 2026.

  • Root cause: The skip_block_zeroing option in Linux dm-thin let residual 64 KiB blocks leak between tenants.

  • Full remediation: Cloudflare completed the fix by September 19, 2026, with no customer action required.

Cloudflare has patched a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes, which is built on Containers. Security researcher Oren Yomtov from Accomplish reported the flaw on September 4, 2026, through Cloudflare's HackerOne bug bounty program, and Cloudflare says it has no evidence that customer data has been compromised. 

How the Storage Flaw Exposed Cross-Tenant Data

Cloudflare Containers run each workload inside a dedicated virtual machine powered by the Firecracker VMM, using Linux device mapper thin provisioning to allocate writable root disks. 

The affected storage pools used a 64 KiB thin-block size, and when a thin volume was deleted, its physical blocks returned to a pool shared across multiple customer accounts. With block zeroing disabled, a small write to a reassigned block changed only that portion, leaving the rest able to retain data from the block's previous owner.

The proof of concept performed the following steps:

  • Create a container using a Workers Paid account.
  • Open the writable root disk at /dev/vdc.
  • Read the disk and record a baseline.
  • Write one 4 KiB block into each selected 64 KiB region corresponding to ext4 free space.
  • Read the resulting blocks again.
  • Examine only the portions not overwritten by the new container.
What a Workers Paid Account Could Recover

Using a Workers Paid account, researchers demonstrated recovering residual disk blocks previously used by other Containers on the same host. The technique could not target a specific customer, workload, or host, and residual data was not guaranteed to be present. 

Across placements spanning four continents, recovered material included directory structures, database pages, and structurally complete SQLite databases. Researchers did not demonstrate any modification of another customer's active data or impact to workload availability.

Cloudflare applied a fix across the Containers fleet, requiring no customer-side configuration changes, removing the skip_block_zeroing setting, retiring running container disks, and clearing cached image snapshots; cleanup was completed by September 19, 2026. 

“Cloudflare has patched this vulnerability and remediation does not require any further action by Cloudflare customers,” the company advisory said.

After reviewing historical disk-I/O telemetry, the company said it found no evidence of malicious exploitation beyond authorized validation activity from researchers and its own engineers.

In May, CISA warned of a severe CopyFail Linux vulnerability that was under active exploitation (CVE-2026-31431).

Explore More

Most Popular

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours013.5924-09-2026
2Уязвимости в LXD, Incus, GitLab, Radicle, ядре Linux, WordPress, OpenVPN, Flatpak, NTFS-3G, FreeRDP, CUPS, Dovecot012.4927-09-2026
3Hacker ‘IamNotAVillain’ Leaks 150 GB of Alleged Italian Government Data012.2625-09-2026
4Revolut breach exposes authentication-authorization gap018.8617-09-2026
5OpenAI pauses most powerful AI training after thousands of sandbox escapes uncovered09.9427-09-2026
6LeakWatch KW 37/2026: Berlins Datenleck wirkt nach, Microsoft stopft 966 Löcher und ein Rootkit versteckt sich im Arbeitsspeicher013.3313-09-2026
7Telekom: Mehr Sicherheit für diese Speedport-Router019.9825-09-2026
8Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд0926-09-2026
9ShinyHunters FBI Data Breach: Leaked Spreadsheet Names Staff in China, Russia and HUMINT Roles06.5824-09-2026
10MacSync macOS Stealer Returns With Binary Payloads and iCloud Tricks01325-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 11.48. Источник: www.technadu.com.