if (index < bounds) {
index2 = array1[index];
... array2[index2];
}
If the compiler speculates both array accesses above the bounds check, then the first one can still succeed (i.e. not produce a NaR) while accessing attacker-controlled memory for the value of index2.You could obviously fix this by never generating code that does double speculation, but you could also do that by modifying a conventional OoO microarchitecture.