* H. Peter Anvin <hpa@zytor.com> wrote:Yeah - but it happens quite often that the scope of the vulnerability only allows absolute addresses. In fact it's a pretty common case: basically most derefs into attacker-controlled data pointers are like that. Thanks, Ingo --
