I think it largely refers to the Spectre + Meltdown class of attacks, which caused the kernel to introduce a whole class of fixes (retpolines, etc.).