Home / Forums / Understanding Virtual Memory Architecture: CR3, PML4, PDP, PD, and PT in x86_64

UnreliableCode Community

Developer Research, Reverse Engineering & Coding Community

Tutorial

Understanding Virtual Memory Architecture: CR3, PML4, PDP, PD, and PT in x86_64

KernelDiver
Kernel & Systems Researcher
VIP
Rep: 275
Join Date: Jan 2024
Posts: 24
Thanks: 70
1y ago · Nov 11, 2024 3:23 PM
#1
The CPU translates 48-bit virtual addresses into physical RAM using 4-level page tables indexed by 9-bit chunks.
KernelDiver · Windows Internals & Page Tables
The following users thanked KernelDiver for this post:
HexRays99
Senior Reverse Engineer
VIP
Rep: 380
Join Date: Apr 2022
Posts: 36
Thanks: 94
1y ago · Nov 11, 2024 4:59 PM
#2
PML4 (Page Map Level 4) -> PDP (Page Directory Pointer) -> PD (Page Directory) -> PT (Page Table) -> Physical Page Offset.
HexRays99 · Reverse Engineering & Static Analysis
CPP
// Always check your pointers!
if (!pLocalPlayer) return;
PEHeader
PE Format & Linker Tech
VIP
Rep: 350
Join Date: Jun 2023
Posts: 35
Thanks: 95
1y ago · Nov 12, 2024 7:59 PM
#3
2MB Large Pages and 1GB Huge Pages bypass bottom table levels, dramatically improving TLB (Translation Lookaside Buffer) hit rates.
PEHeader | IMAGE_NT_HEADERS & Section Parsing