diff --git a/volatility3/framework/layers/intel.py b/volatility3/framework/layers/intel.py index 89ffcdbaf..94b15d3a0 100644 --- a/volatility3/framework/layers/intel.py +++ b/volatility3/framework/layers/intel.py @@ -329,5 +329,11 @@ class WindowsIntelPAE(WindowsMixin, IntelPAE): class WindowsIntel32e(WindowsMixin, Intel32e): + # TODO: Fix appropriately in a future release. + # Currently just a temprorary workaround to deal with custom bit flag + # in the PFN field for pages in transition state. + # See https://github.com/volatilityfoundation/volatility3/pull/475 + _maxphyaddr = 45 + def _translate(self, offset: int) -> Tuple[int, int, str]: return self._translate_swap(self, offset, self._bits_per_register // 2) diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index f402c800f..997175fba 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -972,7 +972,12 @@ class CONTROL_AREA(objects.StructType): # If the entry is not a valid physical address then see if it is in transition. elif mmpte.u.Trans.Transition == 1: - physoffset = mmpte.u.Trans.PageFrameNumber << 12 + # TODO: Fix appropriately in a future release. + # Currently just a temprorary workaround to deal with custom bit flag + # in the PFN field for pages in transition state. + # See https://github.com/volatilityfoundation/volatility3/pull/475 + physoffset = (mmpte.u.Trans.PageFrameNumber & (( 1 << 33 ) - 1 ) ) << 12 + yield physoffset, file_offset, self.PAGE_SIZE # Go to the next PTE entry