<?xml version="1.0" encoding='utf-8'?>
<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.1//EN" "http://www.wapforum.org/DTD/wml_1.1.xml">
<wml>
<card id="card1" title="Transient execution CPU vulnerability - Page 28 - Wikipedia">
<p>
<a accesskey="1" href="page.php?w=Transient_execution_CPU_vulnerability&amp;p=27">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Transient_execution_CPU_vulnerability&amp;p=29">3.Next</a>
</p>
<p>reads of control registers; and , which leaks TSC_AUX register values. Mitigations include microcode updates, Linux kernel patches (<code>tsa=</code> tunable), and optional use of the <code>VERW</code> instruction--albeit with potential performance costs.</p>

<p>In September 2025, researchers at ETH Zurich disclosed <b>VMScape</b> , a <a href="page.php?w=Spectre_%28security_vulnerability%29">Spectre</a>-BTI-style transient execution attack that exploits incomplete isolation of the branch predictor between guest virtual machines and host user-space</p><p>
<a accesskey="1" href="page.php?w=Transient_execution_CPU_vulnerability&amp;p=27">1.Previous</a><br />
<a accesskey="3" href="page.php?w=Transient_execution_CPU_vulnerability&amp;p=29">3.Next</a>
</p>

<do type="prev" label="Search">
        <go href="search.wml"/>
</do>

</card>
</wml>
