ALEXKRI.NET
Resume Contact
← Back

How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Credit where it’s due - this is what a postmortem should look like. Cloudflare Containers ran device mapper thin provisioning with skip_block_zeroing on, so a 4 KiB write could claim a recycled 64 KiB block and serve you the other 60 KiB of whoever had it last. Their own team recovered foreign directory inodes on 20 of 22 nodes across four continents. Reported and merged the same day, 4 September.

Read the source ↗