Skip to content
tag — speculative-execution

grep -rl "speculative-execution" ./articles

#speculative-execution

1 article

The CPU forgets the code and remembers where it jumped. That is enough to read the root hash

2026-10-01Security

VUSEC's Branch Target Reuse attack uses a gap nobody closed: when a JIT engine throws away compiled code and writes new code in the same place, the processor updates what is there but keeps its old prediction of where the jump goes. On a fully patched Intel machine with default mitigations, their Linux exploit pulls the root password hash out of kernel memory at eight bytes a second.