C
calckw22
Recently I got BSOD several times while playing games, and here is the DMP text:
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000004, The thread's stack pointer was outside the legal stack
extents for the thread.
Arg2: ffffa700caba0510, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffffa700caba0468, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2656
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-9A27JQ8
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 2729
Key : Analysis.Memory.CommitPeak.Mb
Value: 85
Key : Analysis.System
Value: CreateObject
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
BUGCHECK_CODE: 139
BUGCHECK_P1: 4
BUGCHECK_P2: ffffa700caba0510
BUGCHECK_P3: ffffa700caba0468
BUGCHECK_P4: 0
TRAP_FRAME: a8018101a63ba05c -- (.trap 0xa8018101a63ba05c)
Unable to read trap frame at a8018101`a63ba05c
EXCEPTION_RECORD: ffffa700caba0468 -- (.exr 0xffffa700caba0468)
ExceptionAddress: fffff80772a916a7 (nt!RtlpGetStackLimitsEx+0x0000000000165a97)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000004
Subcode: 0x4 FAST_FAIL_INCORRECT_STACK
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: wwzRetailEgs.e
WATSON_BKT_EVENT: BEX
ERROR_CODE: (NTSTATUS) 0xc0000409 - ??????????????????????,??????????????????????????
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000004
EXCEPTION_STR: 0xc0000409
BAD_STACK_POINTER: ffffa700caba01e8
STACK_TEXT:
ffffa700`caba01e8 fffff807`72a07769 : 00000000`00000139 00000000`00000004 ffffa700`caba0510 ffffa700`caba0468 : nt!KeBugCheckEx
ffffa700`caba01f0 fffff807`72a07b90 : 5059ab76`3da9a461 686901d5`511b01d2 fd0361fa`f585e571 dff1b393`d277b15a : nt!KiBugCheckDispatch+0x69
ffffa700`caba0330 fffff807`72a05f23 : 033509b2`867b9523 f6835b83`78cf53c7 26981f4d`13d0286b 14a2fff5`3c789feb : nt!KiFastFailDispatch+0xd0
ffffa700`caba0510 fffff807`72a916a7 : ffffa700`caba0920 ffffb704`cf692048 ffffa700`caba0710 ffffa700`caba0870 : nt!KiRaiseSecurityCheckFailure+0x323
ffffa700`caba06a0 fffff807`7292bde1 : ffffa700`caba0920 00000000`00000000 000004e8`fffffb30 000004d0`00000003 : nt!RtlpGetStackLimitsEx+0x165a97
ffffa700`caba06d0 fffff807`7292ab86 : ffffb704`cf692048 ffffa700`caba0e20 ffffb704`cf692048 00000000`a0000004 : nt!RtlDispatchException+0xe1
ffffa700`caba08f0 fffff807`729f6612 : 579e7a6f`1716b64a aceae586`f016e4ce a8018101`a63ba05c a11991c4`dc2812e4 : nt!KiDispatchException+0x186
ffffa700`caba0fb0 fffff807`729f65e0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffffb704`cf691f08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
SYMBOL_NAME: nt!KiFastFailDispatch+d0
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.685
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: 0x139_MISSING_GSFRAME_STACKPTR_ERROR_nt!KiFastFailDispatch
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {7b0febb5-6007-4f2b-3d38-57fef278d8d5}
Followup: MachineOwner
---------
kd> !process
PROCESS ffffb90fa0df2340
SessionId: none Cid: 1610 Peb: 928e8d3000 ParentCid: 0a68
DirBase: 315047000 ObjectTable: ffffe1828e1deac0 HandleCount: <Data Not Accessible>
Image: wwzRetailEgs.e
VadRoot ffffb90fa7674d60 Vads 28944 Clone 0 Private 1135299. Modified 665946. Locked 41670.
DeviceMap ffffe18279a0d630
Token ffffe182972d3060
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 3462232
QuotaPoolUsage[NonPagedPool] 3994672
Working Set Sizes (now,min,max) (802347, 50, 345) (3209388KB, 200KB, 1380KB)
PeakWorkingSetSize 1408980
VirtualSize 13477 Mb
PeakVirtualSize 13525 Mb
PageFaultCount 30321853
MemoryPriority FOREGROUND
BasePriority 8
CommitCharge 1892132
Job ffffb90f9eee6060
*** Error in reading nt!_ETHREAD @ ffffb90f9be51080
Continue reading...
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000004, The thread's stack pointer was outside the legal stack
extents for the thread.
Arg2: ffffa700caba0510, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffffa700caba0468, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2656
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-9A27JQ8
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 2729
Key : Analysis.Memory.CommitPeak.Mb
Value: 85
Key : Analysis.System
Value: CreateObject
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
BUGCHECK_CODE: 139
BUGCHECK_P1: 4
BUGCHECK_P2: ffffa700caba0510
BUGCHECK_P3: ffffa700caba0468
BUGCHECK_P4: 0
TRAP_FRAME: a8018101a63ba05c -- (.trap 0xa8018101a63ba05c)
Unable to read trap frame at a8018101`a63ba05c
EXCEPTION_RECORD: ffffa700caba0468 -- (.exr 0xffffa700caba0468)
ExceptionAddress: fffff80772a916a7 (nt!RtlpGetStackLimitsEx+0x0000000000165a97)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000004
Subcode: 0x4 FAST_FAIL_INCORRECT_STACK
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: wwzRetailEgs.e
WATSON_BKT_EVENT: BEX
ERROR_CODE: (NTSTATUS) 0xc0000409 - ??????????????????????,??????????????????????????
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000004
EXCEPTION_STR: 0xc0000409
BAD_STACK_POINTER: ffffa700caba01e8
STACK_TEXT:
ffffa700`caba01e8 fffff807`72a07769 : 00000000`00000139 00000000`00000004 ffffa700`caba0510 ffffa700`caba0468 : nt!KeBugCheckEx
ffffa700`caba01f0 fffff807`72a07b90 : 5059ab76`3da9a461 686901d5`511b01d2 fd0361fa`f585e571 dff1b393`d277b15a : nt!KiBugCheckDispatch+0x69
ffffa700`caba0330 fffff807`72a05f23 : 033509b2`867b9523 f6835b83`78cf53c7 26981f4d`13d0286b 14a2fff5`3c789feb : nt!KiFastFailDispatch+0xd0
ffffa700`caba0510 fffff807`72a916a7 : ffffa700`caba0920 ffffb704`cf692048 ffffa700`caba0710 ffffa700`caba0870 : nt!KiRaiseSecurityCheckFailure+0x323
ffffa700`caba06a0 fffff807`7292bde1 : ffffa700`caba0920 00000000`00000000 000004e8`fffffb30 000004d0`00000003 : nt!RtlpGetStackLimitsEx+0x165a97
ffffa700`caba06d0 fffff807`7292ab86 : ffffb704`cf692048 ffffa700`caba0e20 ffffb704`cf692048 00000000`a0000004 : nt!RtlDispatchException+0xe1
ffffa700`caba08f0 fffff807`729f6612 : 579e7a6f`1716b64a aceae586`f016e4ce a8018101`a63ba05c a11991c4`dc2812e4 : nt!KiDispatchException+0x186
ffffa700`caba0fb0 fffff807`729f65e0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffffb704`cf691f08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
SYMBOL_NAME: nt!KiFastFailDispatch+d0
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.685
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: 0x139_MISSING_GSFRAME_STACKPTR_ERROR_nt!KiFastFailDispatch
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {7b0febb5-6007-4f2b-3d38-57fef278d8d5}
Followup: MachineOwner
---------
kd> !process
PROCESS ffffb90fa0df2340
SessionId: none Cid: 1610 Peb: 928e8d3000 ParentCid: 0a68
DirBase: 315047000 ObjectTable: ffffe1828e1deac0 HandleCount: <Data Not Accessible>
Image: wwzRetailEgs.e
VadRoot ffffb90fa7674d60 Vads 28944 Clone 0 Private 1135299. Modified 665946. Locked 41670.
DeviceMap ffffe18279a0d630
Token ffffe182972d3060
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 3462232
QuotaPoolUsage[NonPagedPool] 3994672
Working Set Sizes (now,min,max) (802347, 50, 345) (3209388KB, 200KB, 1380KB)
PeakWorkingSetSize 1408980
VirtualSize 13477 Mb
PeakVirtualSize 13525 Mb
PageFaultCount 30321853
MemoryPriority FOREGROUND
BasePriority 8
CommitCharge 1892132
Job ffffb90f9eee6060
*** Error in reading nt!_ETHREAD @ ffffb90f9be51080
Continue reading...