mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-29 04:54:51 +02:00
use an alignmemt based on the cpu arch, not the pool header size
this fixes an issue with pool scanning on win10 32-bit samples, because the size of a pool header increased to 16 bytes, but we still want 8 byte alignment on 32-bit machines
This commit is contained in:
@@ -70,7 +70,10 @@ class _POOL_HEADER(objects.Struct):
|
||||
|
||||
# otherwise we have an executive object in the pool
|
||||
else:
|
||||
alignment = pool_header_size
|
||||
if symbols.symbol_table_is_64bit(self._context, symbol_table_name):
|
||||
alignment = 16
|
||||
else:
|
||||
alignment = 8
|
||||
|
||||
# FIXME: calculate and cache this
|
||||
max_optional_headers_length = 0x60
|
||||
|
||||
Reference in New Issue
Block a user