From 2415e985104c698ba0e9994d292c26f74b120cd5 Mon Sep 17 00:00:00 2001 From: eve Date: Fri, 28 Mar 2025 12:35:32 +0000 Subject: [PATCH] Fix `display_type()` issue for `.write` attribute in volshell, or other fuctions Previously, `getattr(volobject, member)` in `display_type()` would incorrectly retrieve method references (e.g., `.write`) instead of the intended object addresses, causing an `AttributeError` when `_display_value()` attempted to access `.vol.offset`. This commit replaces `getattr(volobject, member)` with `volobject.member(member)`, ensuring that the correct object address is retrieved instead of method references. Fixes: #1705 --- volatility3/cli/volshell/generic.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/volatility3/cli/volshell/generic.py b/volatility3/cli/volshell/generic.py index ca1c7b73c..4ebda12a2 100644 --- a/volatility3/cli/volshell/generic.py +++ b/volatility3/cli/volshell/generic.py @@ -503,7 +503,7 @@ class Volshell(interfaces.plugins.PluginInterface): if isinstance(volobject, interfaces.objects.ObjectInterface): # We're an instance, so also display the data try: - value = self._display_value(getattr(volobject, member)) + value = self._display_value(volobject.member(member)) except exceptions.InvalidAddressException: value = self._display_value(renderers.NotAvailableValue()) print(