MmFreePoolMemory
INT64 __fastcall MmFreePoolMemory(UINT64 *a1, UINT64 *rdx0){
ULONG_PTR v2;
ULONG_PTR v3;
unsigned __int64 v4;
int v5;
unsigned int v6;
unsigned int v7;
int v8;
__int64 AnyMultiplexedVm;
char *v10;
__int64 v11;
__int128 v13;
UINT64 a2[2];
__int128 v15;
v2 = *rdx0;
v3 = *a1;
v4 = (*rdx0 >> 12) + ((*rdx0 & 0xFFF) != 0);
v5 = MiDeterminePoolType(*a1);
if( v5 == 32 )
KeBugCheckEx(0x1Au, 0x5305ui64, v3, v2, v6);
if( v5 == 33 )
v7 = 1;
else
v7 = (v5 != 0) + 5;
v8 = v6 | 0x4000;
if( (v6 & 0x8000) == 0 )
v8 = v6;
LODWORD(AnyMultiplexedVm) = v8;
if( (v8 & 0x4000) != 0 )
{
if( (v5 & 1) != 0 )
{
v13 = 0i64;
*(_OWORD *)a2 = 0i64;
v15 = 0i64;
v10 = (char *)MmGetPteBase() + ((v3 >> 9) & 0x7FFFFFFFF8i64);
if( (v5 & 0x20) != 0 )
AnyMultiplexedVm = *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1368i64) + 256i64;
else
AnyMultiplexedVm = (__int64)MiGetAnyMultiplexedVm(2i64);
MiDeleteSystemPagableVm(AnyMultiplexedVm, 0i64, (unsigned __int64)v10, v4, (v8 & 0x40000000) != 0, &v13);
v11 = a2[1];
MiReturnCommit(
*(_MI_PARTITION **)(qword_140C4E388 + 8i64 * *(unsigned __int16 *)(AnyMultiplexedVm + 174)),
a2[1] - *((_QWORD *)&v13 + 1));
LOWORD(AnyMultiplexedVm) = v8;
}
else
{
if( (v8 & 0x40000000) == 0 && MmProtectFreedNonPagedPool )
LODWORD(AnyMultiplexedVm) = v8 | 0x40000000;
v11 = MiClearNonPagedPtes(v3, v4, AnyMultiplexedVm, 1u);
}
if( v11 )
MiCountSystemPool(v7, v11, 0i64);
}
if( (AnyMultiplexedVm & 0x8000) != 0 )
{
if( v7 == 1 )
_InterlockedExchangeAdd(
(volatile signed __int32 *)(*(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1368i64) + 868i64),
-(int)(v4 >> 9));
MiReturnSystemVa(v3, v2 + v3, v7);
}
return 0i64;
}Referenced by:
MmAllocatePoolMemory
RtlpHpEnvFreeVA
RtlpHpVaMgrCtxFree