Web hosting, domains, email and websites for local business

T3CHS Get Started

Hosting2 min read

Cloudflare Fixes a Flaw That Could Expose Leftover Customer Data

A researcher found that Cloudflare Containers could hand one customer old disk data left by another. Cloudflare fixed it the same day and says no action is needed.

Disclosure: T3CHS sells hosting and domains. This story was written under our editorial policy, apart from sales.

Illustration: Hosting cover art by T3CHS

Key Takeaways

  • Cloudflare Containers could hand one customer old disk data left by another.
  • Cloudflare fixed it the same day it was reported and says customers need to do nothing.
  • A typical small business site does not run on this developer product.

Cloudflare published a detailed report on September 24 about a flaw in two of its developer products. In some cases, a customer could read leftover data that an earlier workload from another customer had left on the same disk.

Background: what kind of hosting a small business needs.

Cloudflare says it fixed the problem the same day it was reported, found no sign that anyone misused it, and that customers do not need to do anything.

What Went Wrong

The issue affected Cloudflare Containers and Sandboxes, which let developers run their own code on Cloudflare's servers. It was found by Oren Yomtov of a company called Accomplish.

When a new workload got disk space, that space was not always wiped first. The cause was a Linux storage setting called skip_block_zeroing. A customer on the Workers Paid plan could read old blocks of data from earlier workloads on the same machine.

Cloudflare said that data could include file system details, database pages and application data.

How Fast It Was Fixed

  • The flaw was reported at 15:26 UTC on September 4.
  • A fix started rolling out at 23:15 UTC that same day.
  • The rollout was complete on September 7.
  • Cleanup of stored snapshots finished on September 19.

Who It Affects

This is a developer product. A typical small business website on ordinary hosting, or even one that uses Cloudflare for speed and security, does not run on Containers. If you are not sure, ask whoever built your site.

Why It Is Worth Knowing

Shared hosting and cloud services all put many customers on the same hardware. That is what makes them affordable. It also means the host has to keep each customer's data apart.

This report is a good example of how a provider should handle a flaw. It fixed it fast, explained it in public and said clearly who was affected. It is fair to ask your own host how it would tell you about a problem like this.

Terms in This Story

Remote code execution
A bug that lets an attacker run their own code on your server from afar.
Shared hosting
Many sites on one server, sharing its power.

Sources

  1. Cloudflare blog post on the Containers cross tenant issueblog.cloudflare.com

Spot an error? Tell us through our contact form. We fix mistakes in the open, as our corrections policy explains.

About the T3CHS News Desk

The desk covers hosting, security, domains, email and AI tools for people who run a small business. Every story links its sources and follows our editorial policy.

More stories from the desk