search
dm-thin
Trends
- 1Cloudflare fixes cross-tenant data exposure in Containers sandboxes●🤖 Cloudflare Containers/Sandboxes cross-tenant data exposure: dm-thin storage pools ran with skip_block_zeroing, so a Wo
A cross-tenant data exposure flaw in Cloudflare's Containers and Sandboxes has been disclosed and fixed. The issue stemmed from dm-thin storage pools running with skip_block_zeroing enabled, meaning newly written 4 KiB pages into unmapped 64 KiB blocks could leave residual data on raw devices. A Workers Paid tenant could reportedly read up to 60 KiB of data left behind by a previous tenant from /dev/vdc. Cloudflare has patched the issue, and security communities are discussing the implications of shared-storage isolation failures in multi-tenant cloud platforms.
- 2Cloudflare Containers' disk isolation questioned over unzeroed thin-pool blocks●A microVM per tenant does not isolate the disk if the thin pool hands out recycled blocks unzeroed. Cloudflare Container
A discussion is underway about whether Cloudflare's Containers service, which gives each tenant a Firecracker microVM on dm-thin provisioning with block zeroing skipped, can truly isolate tenant disk data. Because the thin pool uses 64 KiB blocks and hands out recycled blocks unzeroed, a tenant writing 4 KiB could read neighboring data from a previous tenant in the remaining space.