The ASLR predictability is actually a weakness in the NX-emulation patch carried by Fedora and Ubuntu. If this was done on a PAE system (even 32bit), it would have been pretty unfeasible. That said, it's still good research. I wrote up a little more about it here: