22: 0f 01 c3 vmresume 25: 48 89 4c 24 08 mov %rcx,0x8(%rsp) 2a: 59 pop %rcx <rip>: 2b: 0f 96 81 88 56 00 00 setbe 0x5688(%rcx) 32: 48 89 81 00 03 00 00 mov %rax,0x300(%rcx) 39: 48 89 99 18 03 00 00 mov %rbx,0x318(%rcx) %rcx should be pointing to the vcpu_vmx structure, but it's not even canonical: 1ffff10035842e78.