Meltdown & specter appear to vindicate viewing caches as programmable & hence likely exploitable automata. AFAIK, due to @paxteam's NOEXEC.
1
3
7
Replying to @sergeybratus
if you mean the TLB hacking based PAGEEXEC method, its origins are somewhere else as mentioned in pax.grsecurity.net/docs/page… ;)

Jan 4, 2018 · 11:01 AM UTC

1
3
Replying to @paxteam
Plex86 sure deserves credit. What I meant was, PAGEEXEC mapped out & programmed de facto extra states of the (split) x86 TLB cache.
1