From f148a9344504634257ba114a0f56bb4ae66f7d39 Mon Sep 17 00:00:00 2001 From: mmadersbacher Date: Tue, 18 Aug 2026 20:11:30 +0200 Subject: [PATCH] Fix capabilities plugin on kernels before 6.3 kernel_cap_t only handles the 6.3+ layout and raised for everything else. Before 6.3 the same name exists as a typedef of kernel_cap_struct, whose implementation already decodes the two-element cap array, so fall back to it instead of raising. --- volatility3/framework/symbols/linux/extensions/__init__.py | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/volatility3/framework/symbols/linux/extensions/__init__.py b/volatility3/framework/symbols/linux/extensions/__init__.py index 836810a6d..8068a3e97 100644 --- a/volatility3/framework/symbols/linux/extensions/__init__.py +++ b/volatility3/framework/symbols/linux/extensions/__init__.py @@ -2375,9 +2375,8 @@ class kernel_cap_t(kernel_cap_struct): # In kernels >= 6.3 kernel_cap_t::val is a u64 cap_value = self.val else: - raise exceptions.VolatilityException( - "Unsupported kernel capabilities implementation" - ) + # Before 6.3 kernel_cap_t is a typedef of kernel_cap_struct + return super().get_capabilities() return cap_value & self.get_kernel_cap_full()