I wonder if it would be possible to peg the kernel to one processor core (or a subset of the cores) and userspace to the remainder of the cores. As I understand it, all of the memory caches that are being exploited to leak information are per-core, so that would give a blanket guard against kernel->userspace leaks via cache timing.