MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: ffffa900c5eaf6e8
Arg3: 0000000000020000
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 750
Key : Analysis.Elapsed.mSec
Value: 1193
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 328
Key : Analysis.Init.Elapsed.mSec
Value: 2891
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x1a
Key : Bugcheck.Code.TargetModel
Value: 0x1a
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: MEMORY_CORRUPTION_ONE_BIT
Key : Failure.Hash
Value: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
Key : MemoryManagement.PFN
Value: 0x20
BUGCHECK_CODE: 1a
BUGCHECK_P1: 41792
BUGCHECK_P2: ffffa900c5eaf6e8
BUGCHECK_P3: 20000
BUGCHECK_P4: 0
FILE_IN_CAB: 050225-7156-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffab0ae8f15080
MEMORY_CORRUPTOR: ONE_BIT
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: msedgewebview2
STACK_TEXT:
ffffcf86`43777378 fffff807`9884d4b6 : 00000000`0000001a 00000000`00041792 ffffa900`c5eaf6e8 00000000`00020000 : nt!KeBugCheckEx
ffffcf86`43777380 fffff807`9884bb87 : 00000000`00020000 00000000`00020000 00000000`00000001 ffffa900`c5eaf6e0 : nt!MiDecommitHandlePageFileFormatPte+0x212
ffffcf86`437773e0 fffff807`9884a9a1 : ffffab0a`00000082 ffffab0a`e821c480 ffffab0a`00000000 ffffab0a`e821c080 : nt!MiDeleteVa+0x197
ffffcf86`43777460 fffff807`989e1e3e : 00000000`00000000 ffffab0a`00000000 ffffcf86`00000082 ffffffff`ffffffff : nt!MiDeleteVaDirect+0x2b1
ffffcf86`43777580 fffff807`989e1c5b : 00000000`00000000 fffff807`988841af ffffab0a`e821c2e0 7fffffff`fffffffc : nt!MiDeletePagablePteRange+0x1ba
ffffcf86`43777840 fffff807`98e98fe0 : 00000000`00000000 ffffcf86`43777900 ffffab0a`e9404b80 fffff807`9888ef13 : nt!MiDeleteVirtualAddresses+0x4b
ffffcf86`43777890 fffff807`98e98da1 : 0000018b`cc340000 ffffab0a`e9404b80 0000018b`cc340000 00000000`00000000 : nt!MiDeleteVad+0x180
ffffcf86`43777940 fffff807`98eb501b : ffffab0a`e9404b80 ffffcf86`437779e9 0000018b`cc340000 00000000`00000000 : nt!MiUnmapVad+0x49
ffffcf86`43777970 fffff807`98eb4e5f : ffffffff`ffffffff 7fffffff`00000008 ffffab0a`dc6afa20 00000000`00000000 : nt!MiUnmapViewOfSection+0x177
ffffcf86`43777a50 fffff807`98c8ef58 : ffffab0a`e8f15080 00000000`00000000 ffffab0a`e8f15080 ffffab0a`e821c080 : nt!NtUnmapViewOfSectionEx+0x9f
ffffcf86`43777aa0 00007ff8`c1ddfb94 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000073`811ff328 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`c1ddfb94
MODULE_NAME: hardware
IMAGE_NAME: memory_corruption
STACK_COMMAND: .process /r /p 0xffffab0ae821c080; .thread 0xffffab0ae8f15080 ; kb
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: fffffe80eb0fdce0
Arg3: 0000000020000000
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 750
Key : Analysis.Elapsed.mSec
Value: 767
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 312
Key : Analysis.Init.Elapsed.mSec
Value: 2336
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x1a
Key : Bugcheck.Code.TargetModel
Value: 0x1a
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: MEMORY_CORRUPTION_ONE_BIT
Key : Failure.Hash
Value: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
Key : MemoryManagement.PFN
Value: 0x20000
BUGCHECK_CODE: 1a
BUGCHECK_P1: 41792
BUGCHECK_P2: fffffe80eb0fdce0
BUGCHECK_P3: 20000000
BUGCHECK_P4: 0
FILE_IN_CAB: 050225-8265-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffff878142f0c080
MEMORY_CORRUPTOR: ONE_BIT
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: msedgewebview2
STACK_TEXT:
ffffa60c`a4067378 fffff800`8c04d4b6 : 00000000`0000001a 00000000`00041792 fffffe80`eb0fdce0 00000000`20000000 : nt!KeBugCheckEx
ffffa60c`a4067380 fffff800`8c04bb87 : 00000000`20000000 00000000`20000000 00000000`00000001 fffffe80`eb0fdcd8 : nt!MiDecommitHandlePageFileFormatPte+0x212
ffffa60c`a40673e0 fffff800`8c04a9a1 : ffff8781`00000082 ffff8781`42f0a480 00000000`00000000 ffff8781`42f0a080 : nt!MiDeleteVa+0x197
ffffa60c`a4067460 fffff800`8c1e1e3e : 00000000`00000000 ffff8781`00000000 ffffa60c`00000082 ffffffff`ffffffff : nt!MiDeleteVaDirect+0x2b1
ffffa60c`a4067580 fffff800`8c1e1c5b : 00000000`00000000 fffff800`8c0841af ffff8781`42f0a2e0 7fffffff`fffffffc : nt!MiDeletePagablePteRange+0x1ba
ffffa60c`a4067840 fffff800`8c698fe0 : 00000000`00000000 ffffa60c`a4067900 ffff8781`42985980 fffff800`8c08ef13 : nt!MiDeleteVirtualAddresses+0x4b
ffffa60c`a4067890 fffff800`8c698da1 : 000001d6`13000000 ffff8781`42985980 000001d6`13000000 00000000`00000000 : nt!MiDeleteVad+0x180
ffffa60c`a4067940 fffff800`8c6b501b : ffff8781`42985980 ffffa60c`a40679e9 000001d6`13000000 00000000`00000000 : nt!MiUnmapVad+0x49
ffffa60c`a4067970 fffff800`8c6b4e5f : ffffffff`ffffffff 7fffffff`00000008 ffff8781`366aaa00 00000000`00000000 : nt!MiUnmapViewOfSection+0x177
ffffa60c`a4067a50 fffff800`8c48ef58 : ffff8781`42f0c080 00000000`00000000 ffff8781`42f0c080 ffff8781`42f0a080 : nt!NtUnmapViewOfSectionEx+0x9f
ffffa60c`a4067aa0 00007ffa`a221fb94 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000001c`467feea8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`a221fb94
MODULE_NAME: hardware
IMAGE_NAME: memory_corruption
STACK_COMMAND: .process /r /p 0xffff878142f0a080; .thread 0xffff878142f0c080 ; kb
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: fffff4bffe2ec138
Arg3: 0000000000008000
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 734
Key : Analysis.Elapsed.mSec
Value: 755
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 281
Key : Analysis.Init.Elapsed.mSec
Value: 2558
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x1a
Key : Bugcheck.Code.TargetModel
Value: 0x1a
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: MEMORY_CORRUPTION_ONE_BIT
Key : Failure.Hash
Value: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
Key : MemoryManagement.PFN
Value: 0x8
BUGCHECK_CODE: 1a
BUGCHECK_P1: 41792
BUGCHECK_P2: fffff4bffe2ec138
BUGCHECK_P3: 8000
BUGCHECK_P4: 0
FILE_IN_CAB: 050225-7265-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffe386b6ccd080
MEMORY_CORRUPTOR: ONE_BIT
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: taskhostw.exe
STACK_TEXT:
ffff870e`00a57168 fffff804`b924d4b6 : 00000000`0000001a 00000000`00041792 fffff4bf`fe2ec138 00000000`00008000 : nt!KeBugCheckEx
ffff870e`00a57170 fffff804`b924bb87 : 00000000`00008000 00000000`00008000 00000000`00000001 fffff4fa`5fff1760 : nt!MiDecommitHandlePageFileFormatPte+0x212
ffff870e`00a571d0 fffff804`b924a9a1 : ffffe386`00000082 ffffe386`b6d5d480 00000000`00000000 ffffe386`b6d5d080 : nt!MiDeleteVa+0x197
ffff870e`00a57250 fffff804`b93e1e3e : 00000000`00000000 ffffe386`00000000 ffff870e`00000082 ffffffff`ffffffff : nt!MiDeleteVaDirect+0x2b1
ffff870e`00a57370 fffff804`b93e1c5b : 00000000`00000000 fffff804`b92841af ffffe386`b6d5d2e0 7fffffff`fffffffc : nt!MiDeletePagablePteRange+0x1ba
ffff870e`00a57630 fffff804`b9898fe0 : 00000000`00000000 ffff870e`00a576f0 ffffe386`b9aa9c40 ffff870e`00a576f0 : nt!MiDeleteVirtualAddresses+0x4b
ffff870e`00a57680 fffff804`b9898da1 : 00007ffc`5d7e0000 ffffe386`b9aa9c40 ffffe386`b9aa9c68 00000000`00000000 : nt!MiDeleteVad+0x180
ffff870e`00a57730 fffff804`b9898d27 : ffffe386`b9aa9c40 00000000`00000000 ffffe386`b6ccd080 00000000`00000000 : nt!MiUnmapVad+0x49
ffff870e`00a57760 fffff804`b9898b4b : ffffe386`b9aad8e0 ffffe386`b6ccd080 ffffe386`b6ccd080 ffffe386`b6ccd080 : nt!MiCleanVad+0x2b
ffff870e`00a57790 fffff804`b9898182 : ffffe386`00000000 ffffe386`b6d5d268 ffff870e`00a57900 00000000`00000000 : nt!MmCleanProcessAddressSpace+0xfb
ffff870e`00a57810 fffff804`b9897c76 : ffffe386`b6d5d080 ffffe386`b6d5d080 ffff870e`00a57900 00000000`00000000 : nt!PspRundownSingleProcess+0xc2
ffff870e`00a578a0 fffff804`b995c42b : 00000077`30a89000 00000000`00000000 00000000`00000001 ffffe386`b6ccd080 : nt!PspExitLastThread+0xe6
ffff870e`00a57930 fffff804`b9958777 : ffffe386`b6d5d080 00000000`00000001 ffffe386`b6ccd080 ffffe386`b6d5d080 : nt!PspExitThread+0x7bb
ffff870e`00a57a20 fffff804`b968ef58 : ffffe386`b6d5d080 ffffe386`b6ccd080 01dbbb44`99372fa1 000d0000`000000d5 : nt!NtTerminateProcess+0x117
ffff870e`00a57aa0 00007ffc`6011c544 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000077`3088f678 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`6011c544
MODULE_NAME: hardware
IMAGE_NAME: memory_corruption
STACK_COMMAND: .process /r /p 0xffffe386b6d5d080; .thread 0xffffe386b6ccd080 ; kb
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffe78144cfb000, memory referenced.
Arg2: 0000000000000000, X64: bit 0 set if the fault was due to a not-present PTE.
bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the processor decided the fault was due to a corrupted PTE.
bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
- ARM64: bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: fffff807a1f4f1c0, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Type
Value: Read
Key : Analysis.CPU.mSec
Value: 718
Key : Analysis.Elapsed.mSec
Value: 2040
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 281
Key : Analysis.Init.Elapsed.mSec
Value: 2439
Key : Analysis.Memory.CommitPeak.Mb
Value: 80
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x50
Key : Bugcheck.Code.TargetModel
Value: 0x50
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_R_(null)_nt!MiCompressRelocations
Key : Failure.Exception.IP.Address
Value: 0xfffff807a1f4f1c0
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x94f1c0
Key : Failure.Hash
Value: {e6bcedbe-afd9-7667-8c19-63548073ed13}
BUGCHECK_CODE: 50
BUGCHECK_P1: ffffe78144cfb000
BUGCHECK_P2: 0
BUGCHECK_P3: fffff807a1f4f1c0
BUGCHECK_P4: 0
FILE_IN_CAB: 050225-8281-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffae0710233040
READ_ADDRESS: fffff807a25c34c0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
ffffe78144cfb000
MM_INTERNAL_CODE: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: chrome.exe
STACK_TEXT:
ffffd603`1dc86c58 fffff807`a1ca54a8 : 00000000`00000050 ffffe781`44cfb000 00000000`00000000 ffffd603`1dc86ec0 : nt!KeBugCheckEx
ffffd603`1dc86c60 fffff807`a18913cf : ffffe781`44cfb000 00000000`00001000 00000000`00000002 fffff807`a1600000 : nt!MiSystemFault+0x43288c
ffffd603`1dc86d50 fffff807`a1c8aacb : 00000000`00000000 00000000`001b3ce0 00000000`00000b3d 00000000`00000080 : nt!MmAccessFault+0x2ff
ffffd603`1dc86ec0 fffff807`a1f4f1c0 : 00000000`00000000 00000001`815e5718 00000000`000017f0 ffffe781`44cdd000 : nt!KiPageFault+0x38b
ffffd603`1dc87050 fffff807`a1ee8b76 : ffffe781`44cdd000 ffffd603`1dc8730a 00000000`000018a4 ffffe781`44d14000 : nt!MiCompressRelocations+0x260
ffffd603`1dc870c0 fffff807`a20ca656 : ffffd603`1dc87510 ffffd603`1dc87510 ffffd603`1dc87320 ffffd603`1dc87510 : nt!MiRelocateImage+0x59a
ffffd603`1dc87220 fffff807`a1eb7669 : 00000000`00000000 00000000`00000002 00000000`00000000 00000000`00000002 : nt!MiCreateNewSection+0x211946
ffffd603`1dc87370 fffff807`a1eb6ab8 : 00000000`00000002 ffffae07`128a14d0 ffffd603`1dc873c0 ffffd603`1dc873c0 : nt!MiCreateImageOrDataSection+0x389
ffffd603`1dc87490 fffff807`a1e804e7 : ffffd603`1dc87688 00000000`11000000 ffffd603`1dc877f0 ffffae07`129f0080 : nt!MiCreateSection+0xf8
ffffd603`1dc87610 fffff807`a1e7ff3d : ffffd603`1dc87758 fffff807`00000005 ffffd603`1dc877c8 00000000`00000fff : nt!MiCreateSectionCommon+0x293
ffffd603`1dc876f0 fffff807`a1e7f891 : ffffd603`1dc87930 00000000`0000006c ffffd603`1dc87960 00000000`00000000 : nt!PfSnGetSectionObject+0x33d
ffffd603`1dc878a0 fffff807`a193bf92 : ffffae07`10233040 ffffae07`10233040 ffffae07`047b6c20 ffffae07`10257000 : nt!PfSnPopulateReadList+0x271
ffffd603`1dc87a00 fffff807`a1a4d1fa : ffffae07`10233040 ffffae07`10233040 fffff807`a193bde0 ffffae07`047b6c20 : nt!ExpWorkerThread+0x1b2
ffffd603`1dc87bb0 fffff807`a1c7ca94 : ffff9901`8ef4e180 ffffae07`10233040 fffff807`a1a4d1a0 ffffae07`1022d5e0 : nt!PspSystemThreadStartup+0x5a
ffffd603`1dc87c00 00000000`00000000 : ffffd603`1dc88000 ffffd603`1dc81000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x34
SYMBOL_NAME: nt!MiCompressRelocations+260
MODULE_NAME: nt
IMAGE_VERSION: 10.0.26100.3775
STACK_COMMAND: .process /r /p 0xffffae07046b5040; .thread 0xffffae0710233040 ; kb
IMAGE_NAME: ntkrnlmp.exe
BUCKET_ID_FUNC_OFFSET: 260
FAILURE_BUCKET_ID: AV_R_(null)_nt!MiCompressRelocations
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {e6bcedbe-afd9-7667-8c19-63548073ed13}
Followup: MachineOwner
---------
[SMBIOS Data Tables v3.3]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 2492 bytes]
[BIOS Information (Type 0) - Length 26 - Handle 0000h]
Vendor American Megatrends International, LLC.
BIOS Version F57
BIOS Starting Address Segment f000
BIOS Release Date 03/22/2024
BIOS ROM Size 1000000
BIOS Characteristics
07: - PCI Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
17: - BIOS ROM Socketed
19: - EDD Supported
20: - NEC 9800 J-Floppy Supported
21: - Toshiba J-Floppy Supported
22: - 360KB Floppy Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
26: - Print Screen Device Supported
28: - Serial Services Supported
29: - Printer Services Supported
30: - CGA/Mono Services Supported
32: - BIOS Vendor Reserved
BIOS Characteristic Extensions
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Enable Targeted Content Distribution
11: - UEFI Specification Supported
BIOS Major Revision 5
BIOS Minor Revision 17
EC Firmware Major Revision 255
EC Firmware Minor Revision 255
Extended BIOS ROM Size 16 MB
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer Gigabyte Technology Co., Ltd.
Product Name A320M-S2H
Version Default string
Serial Number Default string
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber Default string
Family Default string
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
Manufacturer Gigabyte Technology Co., Ltd.
Product A320M-S2H-CF
Version Default string
Serial Number Default string
Asset Tag
Feature Flags 09h
00: - Motherboard
03: - Replaceable
Location Default string
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 22 - Handle 0003h]
Manufacturer Default string
Chassis Type Desktop
Version Default string
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 0
Contained Element Size 3
[Onboard Devices Information (Type 10) - Length 6 - Handle 0004h]
Note: The On Board Device Information (Type 10) struct is obsolete as of SMBIOs spec v2.6 Number of Devices 1
01: Type Video [enabled]
01: Description To Be Filled By O.E.M.
[OEM Strings (Type 11) - Length 5 - Handle 0005h]
Number of Strings 1
1 Default string
[System Configuration Options (Type 12) - Length 5 - Handle 0006h]
[ (Type 256) - Length 9 - Handle 0008h]
[ (Type 256) - Length 31 - Handle 0009h]
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 000ah]
[Physical Memory Array (Type 16) - Length 23 - Handle 000bh]
Location 03h - SystemBoard/Motherboard
Use 03h - System Memory
Memory Error Correction 03h - None
Maximum Capacity 134217728KB
Memory Error Inf Handle 000ah
Number of Memory Devices 4
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 000ch]
Starting Address 00000000h
Ending Address 002fffffh
Memory Array Handle 000bh
Partition Width 02
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 000dh]
Starting Address 00400000h
Ending Address 010fffffh
Memory Array Handle 000bh
Partition Width 02
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[Cache Information (Type 7) - Length 27 - Handle 000eh]
Socket Designation L1 - Cache
Cache Configuration 0180h - WBEnabled Int NonSocketed L1
Maximum Cache Size 0180h - 384K
Installed Size 0180h - 384K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 8-way Set-Associative
Maximum Cache Size 2 180 - 00000384l Kb
Installed Cache Size 2 180 - 00000384l Kb
[Cache Information (Type 7) - Length 27 - Handle 000fh]
Socket Designation L2 - Cache
Cache Configuration 0181h - WBEnabled Int NonSocketed L2
Maximum Cache Size 0c00h - 3072K
Installed Size 0c00h - 3072K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 8-way Set-Associative
Maximum Cache Size 2 c00 - 00003072l Kb
Installed Cache Size 2 c00 - 00003072l Kb
[Cache Information (Type 7) - Length 27 - Handle 0010h]
Socket Designation L3 - Cache
Cache Configuration 0182h - WBEnabled Int NonSocketed L3
Maximum Cache Size 8200h - 32768K
Installed Size 8200h - 32768K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 16-way Set-Associative
Maximum Cache Size 2 80000200 - 00032768l Kb
Installed Cache Size 2 80000200 - 00032768l Kb
[Processor Information (Type 4) - Length 48 - Handle 0011h]
Socket Designation AM4
Processor Type Central Processor
Processor Family 6bh - AMD Zen Processor Family
Processor Manufacturer Advanced Micro Devices, Inc.
Processor ID 120fa200fffb8b17
Processor Version AMD Ryzen 5 5600X 6-Core Processor
Processor Voltage 8bh - 1.1V
External Clock 100MHz
Max Speed 4650MHz
Current Speed 3700MHz
Status Enabled Populated
Processor Upgrade Socket AM4
L1 Cache Handle 000eh
L2 Cache Handle 000fh
L3 Cache Handle 0010h
Serial Number
Asset Tag Number
Part Number Unknown
Core Count 6
Core Enabled 6
Thread Count 12
Processor Characteristics fc
Enabled Characteristics:
0x 2: 64-bit Capable
0x 3: Multi-Core
0x 4: Hardware Thread
0x 5: Execute Protection
0x 6: Enhanced Virtualization
0x 7: Power/Performance Control
Processor Family 2 006bh - AMD Zen Processor Family
Core Count 2 6
Core Enabled 2 6
Thread Count 2 12
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0012h]
[Memory Device (Type 17) - Length 92 - Handle 0013h]
Memory Error Info Handle 0012h
Total Width [Unknown]
Data Width [Unknown]
Size [Not Populated]
Form Factor 02h - Unknown
Device Set [None]
Device Locator DIMM 0
Bank Locator P0 CHANNEL A
Memory Type 02h - Unknown
Type Detail 0004h - Unknown
Speed 0MHz
Manufacturer Unknown
Serial Number
Asset Tag Number [String Not Specified]
Part Number Unknown
Attributes 0
Extended Size 0
Configured Memory Speed 0
Minimum Voltage 0
Maximum Voltage 0
Configured Voltage 0
Memory Technology 2
Memory Operating Mode Capability 4
Firmware Version 6
Module Manufacturer Id 0
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
Extended Speed 0
Extended Configured Memory Speed 0
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0014h]
[Memory Device (Type 17) - Length 92 - Handle 0015h]
Memory Error Info Handle 0014h
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator DIMM 1
Bank Locator P0 CHANNEL A
Memory Type 1ah - DDR4
Type Detail 4080h - Synchronous Unbuffered (Unregistered)
Speed 2133MHz
Manufacturer Kingston
Serial Number
Asset Tag Number [String Not Specified]
Part Number KHX2133C14D4/8G
Attributes 2
Extended Size 0
Configured Memory Speed 2133
Minimum Voltage 1200
Maximum Voltage 1200
Configured Voltage 1200
Memory Technology 3
Memory Operating Mode Capability 8
Firmware Version 6
Module Manufacturer Id 38913
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
Extended Speed 0
Extended Configured Memory Speed 0
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0016h]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Device Handle 0015h
Mem Array Mapped Adr Handle 000dh
Partition Row Position [Unknown]
Interleave Position [Unknown]
Interleave Data Depth [Unknown]
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0017h]
[Memory Device (Type 17) - Length 92 - Handle 0018h]
Memory Error Info Handle 0017h
Total Width [Unknown]
Data Width [Unknown]
Size [Not Populated]
Form Factor 02h - Unknown
Device Set [None]
Device Locator DIMM 0
Bank Locator P0 CHANNEL B
Memory Type 02h - Unknown
Type Detail 0004h - Unknown
Speed 0MHz
Manufacturer Unknown
Serial Number
Asset Tag Number [String Not Specified]
Part Number Unknown
Attributes 0
Extended Size 0
Configured Memory Speed 0
Minimum Voltage 0
Maximum Voltage 0
Configured Voltage 0
Memory Technology 2
Memory Operating Mode Capability 4
Firmware Version 6
Module Manufacturer Id 0
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
Extended Speed 0
Extended Configured Memory Speed 0
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0019h]
[Memory Device (Type 17) - Length 92 - Handle 001ah]
Memory Error Info Handle 0019h
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator DIMM 1
Bank Locator P0 CHANNEL B
Memory Type 1ah - DDR4
Type Detail 4080h - Synchronous Unbuffered (Unregistered)
Speed 2133MHz
Manufacturer Kingston
Serial Number
Asset Tag Number [String Not Specified]
Part Number KHX2133C14D4/8G
Attributes 2
Extended Size 0
Configured Memory Speed 2133
Minimum Voltage 1200
Maximum Voltage 1200
Configured Voltage 1200
Memory Technology 3
Memory Operating Mode Capability 8
Firmware Version 6
Module Manufacturer Id 38913
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
Extended Speed 0
Extended Configured Memory Speed 0
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Device Handle 001ah
Mem Array Mapped Adr Handle 000dh
Partition Row Position [Unknown]
Interleave Position [Unknown]
Interleave Data Depth [Unknown]
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[ (Type 256) - Length 11 - Handle 002fh]
[ (Type 256) - Length 4 - Handle 0031h]
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffff920b4a77eab0, Actual security check cookie from the stack
Arg2: 00005397234bba28, Expected security check cookie
Arg3: ffffac68dcb445d7, Complement of the expected security check cookie
Arg4: 0000000000000000, zero
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 750
Key : Analysis.Elapsed.mSec
Value: 763
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 250
Key : Analysis.Init.Elapsed.mSec
Value: 2267
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0xf7
Key : Bugcheck.Code.TargetModel
Value: 0xf7
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
Key : Failure.Hash
Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
BUGCHECK_CODE: f7
BUGCHECK_P1: ffff920b4a77eab0
BUGCHECK_P2: 5397234bba28
BUGCHECK_P3: ffffac68dcb445d7
BUGCHECK_P4: 0
FILE_IN_CAB: 050225-7875-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffcd07aa03d080
SECURITY_COOKIE: Expected 00005397234bba28 found ffff920b4a77eab0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: explorer.exe
STACK_TEXT:
ffff920b`4a77d7f8 fffff802`8a2f3685 : 00000000`000000f7 ffff920b`4a77eab0 00005397`234bba28 ffffac68`dcb445d7 : nt!KeBugCheckEx
ffff920b`4a77d800 fffff802`8a2bbcd2 : ffff920b`4a77d8e8 ffff920b`4a77dee0 00000000`00000000 00000000`00000000 : nt!_report_gsfailure+0x25
ffff920b`4a77d840 fffff802`8a476606 : 00000000`00000000 fffff802`8a4765c4 00000000`00000000 ffff920b`4a77d930 : nt!_GSHandlerCheckCommon+0x5a
ffff920b`4a77d870 fffff802`8a484f72 : ffff920b`4a77e878 ffff920b`4a77de30 00000000`00000000 ffff920b`4a77d930 : nt!_GSHandlerCheck_SEH+0x42
ffff920b`4a77d8a0 fffff802`8a179e42 : ffff920b`4a77d930 fffff802`89e00000 fffff802`8a6305e7 fffff802`89f20654 : nt!RtlpExecuteHandlerForException+0x12
ffff920b`4a77d8d0 fffff802`8a17afa9 : ffff920b`4a77e920 ffff920b`4a77e560 ffff920b`4a77e920 ffff920b`4a77e060 : nt!RtlDispatchException+0x2d2
ffff920b`4a77e030 fffff802`8a48fa45 : 00000000`c0000005 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0xac9
ffff920b`4a77e740 fffff802`8a48ab82 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0x145
ffff920b`4a77e920 fffff802`8a6305e7 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x442
ffff920b`4a77eab0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtQueryValueKey+0x887
SYMBOL_NAME: nt!_report_gsfailure+25
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.26100.3775
STACK_COMMAND: .process /r /p 0xffffcd07a89dd0c0; .thread 0xffffcd07aa03d080 ; kb
BUCKET_ID_FUNC_OFFSET: 25
FAILURE_BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
Followup: MachineOwner
---------
PnpActivityId : {00000000-0000-0000-0000-000000000000}
PnpActivityTime : 133906472553220059
PnpEventInformation: 0
PnpEventInProgress : 0
PnpProblemCode : 18
PnpVetoType : 0
DeviceId : SWD\DRIVERENUM\{19f2e83e-4150-4cfe-aecd-1f4e17825139}#STEELSERIES_GG_INSTALL_COMPONENT&7&4694103&0
VetoString :