For the side channel crowd:

I wrote about how side channels in serialization can theoretically allow breaking ASLR - with a theoretical worst-case example of how a single round trip of deserializing attacker-controlled data, serializing the result again, and sending the re-serialized data to an attacker could leak an entire pointer:
"Pointer leaks through pointer-keyed data structures"
googleprojectzero.blogspot.com

0

If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/jann/statuses/115271677491955601 on your instance and quote it. (Note that quoting is not supported in Mastodon.)