Thanks for the clarification.
Since then, have you experienced another BSOD? Or your system has been working stably.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Microsoft (R) Windows Debugger Version 10.0.25200.1003 AMD64Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\Users\Reshad\Desktop\030123-14781-01.dmp]Mini Kernel Dump File: Only registers and stack trace are available************* Path validation summary **************Response Time (ms) LocationDeferred srv*Symbol search path is: srv*Executable search path is:Windows 10 Kernel Version 19041 MP (12 procs) Free x64Product: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0xfffff80175400000 PsLoadedModuleList = 0xfffff8017602a2d0Debug session time: Wed Mar 1 13:42:17.473 2023 (UTC + 4:00)System Uptime: 4 days 14:52:39.185Loading Kernel Symbols..Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.Run !sym noisy before .reload to track down problems loading symbols.............................................................................................................................................................................................Loading User SymbolsLoading unloaded module list..................................................For analysis of this file, run !analyze -vnt!KeBugCheckEx:fffff801757fa090 48894c2408 mov qword ptr [rsp+8],rcx ss:ffffea0cb55d3b20=000000000000013910: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************KERNEL_SECURITY_CHECK_FAILURE (139)A kernel component has corrupted a critical data structure. The corruptioncould potentially allow a malicious user to gain control of this machine.Arguments:Arg1: 000000000000001d, An RTL_BALANCED_NODE RBTree entry has been corrupted.Arg2: ffffea0cb55d3e40, Address of the trap frame for the exception that caused the BugCheckArg3: ffffea0cb55d3d98, Address of the exception record for the exception that caused the BugCheckArg4: 0000000000000000, ReservedDebugging Details:------------------KEY_VALUES_STRING: 1Key : Analysis.CPU.mSecValue: 1921Key : Analysis.DebugAnalysisManagerValue: CreateKey : Analysis.Elapsed.mSecValue: 2856Key : Analysis.IO.Other.MbValue: 18Key : Analysis.IO.Read.MbValue: 0Key : Analysis.IO.Write.MbValue: 21Key : Analysis.Init.CPU.mSecValue: 608Key : Analysis.Init.Elapsed.mSecValue: 162111Key : Analysis.Memory.CommitPeak.MbValue: 87Key : Bugcheck.Code.DumpHeaderValue: 0x139Key : Bugcheck.Code.RegisterValue: 0x139Key : Dump.Attributes.AsUlongValue: 8Key : Dump.Attributes.KernelGeneratedTriageDumpValue: 1Key : FailFast.NameValue: INVALID_BALANCED_TREEKey : FailFast.TypeValue: 29FILE_IN_CAB: 030123-14781-01.dmpDUMP_FILE_ATTRIBUTES: 0x8Kernel Generated Triage DumpBUGCHECK_CODE: 139BUGCHECK_P1: 1dBUGCHECK_P2: ffffea0cb55d3e40BUGCHECK_P3: ffffea0cb55d3d98BUGCHECK_P4: 0TRAP_FRAME: ffffea0cb55d48a0 -- (.trap 0xffffea0cb55d48a0)NOTE: The trap frame does not contain all registers.Some register values may be zeroed or incorrect.rax=000000001557cfeb rbx=0000000000000000 rcx=0000000022a57b23rdx=0000000026f43b23 rsi=0000000000000000 rdi=0000000000000000rip=fffff80176bfd9e5 rsp=ffffea0cb55d4a30 rbp=ffffea0cb55d4b30
r8=00000000d62aaf9f r9=0000000095dcd342 r10=00000000e56f6449r11=00000000852fe69b r12=0000000000000000 r13=0000000000000000r14=0000000000000000 r15=0000000000000000iopl=0 nv up ei ng nz na po ncCI!SymCryptSha1AppendBlocks+0x2c5:fffff80176bfd9e5 418b5e2c mov ebx,dword ptr [r14+2Ch] ds:000000000000002c=????????Resetting default scopeEXCEPTION_RECORD: ffffea0cb55d3d98 -- (.exr 0xffffea0cb55d3d98)ExceptionAddress: fffff80175867e97 (nt!RtlRbRemoveNode+0x00000000001d6e47)ExceptionCode: c0000409 (Security check failure or stack buffer overrun)ExceptionFlags: 00000001NumberParameters: 1Parameter[0]: 000000000000001dSubcode: 0x1d FAST_FAIL_INVALID_BALANCED_TREEBLACKBOXBSD: 1 (!blackboxbsd)BLACKBOXNTFS: 1 (!blackboxntfs)BLACKBOXPNP: 1 (!blackboxpnp)BLACKBOXWINLOGON: 1CUSTOMER_CRASH_COUNT: 1PROCESS_NAME: LogonUI.exeERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.EXCEPTION_CODE_STR: c0000409EXCEPTION_PARAMETER1: 000000000000001dEXCEPTION_STR: 0xc0000409STACK_TEXT:ffffea0cb55d3b18 fffff8017580e129 : 0000000000000139 000000000000001d ffffea0cb55d3e40 ffffea0cb55d3d98 : nt!KeBugCheckExffffea0cb55d3b20 fffff8017580e690 : 0000000000000000 ffff8b0a080c9050 8000000600000000 ffffd98a5dc8a0b0 : nt!KiBugCheckDispatch+0x69ffffea0cb55d3c60 fffff8017580c65d : 0000000000000000 ffff8b0a08586b40 ffffa10bde563428 fffff80175606edf : nt!KiFastFailDispatch+0xd0ffffea0cb55d3e40 fffff80175867e97 : ffffa10bc8602100 ffffffffffffffff fffff801757220c7 0000000000000001 : nt!KiRaiseSecurityCheckFailure+0x31dffffea0cb55d3fd8 fffff801757220c7 : 0000000000000001 0000000011000000 ffffa10be58010c0 0000000000000011 : nt!RtlRbRemoveNode+0x1d6e47ffffea0cb55d3ff0 fffff80175721e7a : fffff802e5789000 fffff80175735e79 fffff8017604ef40 fffff80100000000 : nt!RtlpHpSegPageRangeAllocate+0x107ffffea0cb55d4090 fffff80175692d86 : 0000000000011000 0000000000011000 ffff0b1c13846602 ffff8b0a080d18a8 : nt!RtlpHpSegAlloc+0x5affffea0cb55d40f0 fffff80175db4094 : 0000000000000000 0000000000000001 0000000042506343 fffff80175735e79 : nt!ExAllocateHeapPool+0x8f6ffffea0cb55d4230 fffff80175602803 : ffffa10bde8b9000 ffffea0cb55d43b0 0000000000000000 ffffea0c00000000 : nt!ExAllocatePoolWithTag+0x64ffffea0cb55d4280 fffff801756ac338 : fffff8017604ef40 fffff57c0172bc48 ffffeb000a88c850 0a00000382ed7021 : nt!PfSnTraceBufferAllocate+0x1bffffea0cb55d42b0 fffff801756aeff0 : ffffea0cb55d4620 0a00000382ed6121 0000000000000000 0000000300000000 : nt!MiCompleteProtoPteFault+0x808ffffea0cb55d4400 fffff801756ae3a6 : ffffea0cb55d4620 fffff57abe00b958 ffffeb0003ee02c0 0000000000000000 : nt!MiResolveTransitionFault+0xac0ffffea0cb55d44c0 fffff801756a6bb5 : ffffea0cb55d4620 0000000000000000 ffffea0cb55d4600 fffff802e578a000 : nt!MiResolveProtoPteFault+0x1236ffffea0cb55d45c0 fffff801756a4af9 : 0000000000000110 0000000000000000 00000000c0000016 0000000000000000 : nt!MiDispatchFault+0x3d5ffffea0cb55d4700 fffff80175809bd8 : fffff8017604ef40 fffff801756a4c83 0000000000000110 0000000000000000 : nt!MmAccessFault+0x189ffffea0cb55d48a0 fffff80176bfd9e5 : 00000000d6b5ec71 0000000012044ab4 ffff8b0a85593ebd fffff80175809d06 : nt!KiPageFault+0x358ffffea0cb55d4a30 fffff80176bff4d3 : 0000000000000000 ffff8b0a081b2d20 0000000000000000 0000000000000000 : CI!SymCryptSha1AppendBlocks+0x2c5ffffea0cb55d4bf0 fffff80176bfd619 : 0000000000000000 0000000000000000 ffff8b0a081b2cb8 0000000000000400 : CI!SymCryptHashAppendInternal+0xa3ffffea0cb55d4c40 fffff80176c57a0a : fffff802e5770000 ffff8b0a081b2d10 fffff802e5770200 ffff8b0a081b2d10 : CI!SymCryptSha1Append+0x19ffffea0cb55d4c70 fffff80176c43bd3 : 0000000000000000 ffff8b0a081b2cb8 0000000000000400 0000000000000000 : CI!HashpHashBytes+0x5effffea0cb55d4ca0 fffff80176c4614a : 0000000000000000 ffffa10bddf85650 fffff802e5770000 ffff8b0a0005b57e : CI!CipImageGetImageHash+0x3afffffea0cb55d4d70 fffff80176c43050 : 0000000000000000 ffffea0cb55d4fb1 0000000000000000 0000000000000000 : CI!CipCalculateImageHash+0x9affffea0cb55d4de0 fffff80176c42a4c : ffff8b0a081b22c0 ffffa10bddf85650 ffffa10bd7bba0c0 fffff802e5770000 : CI!CipValidateFileHash+0x210ffffea0cb55d4ec0 fffff80176c40eb4 : 000000000000008c 0000000000000000 ffffa10bddf85650 fffff802e5770000 : CI!CipValidateImageHash+0x110ffffea0cb55d5000 fffff80175a53ec1 : ffffea0cb55d5240 fffff802e5770000 000000000000000f fffff802e5770000 : CI!CiValidateImageHeader+0x834ffffea0cb55d5180 fffff80175a5435c : 0000000000000000 ffffa10bd73cacf0 0000000000000000 000000000009a000 : nt!SeValidateImageHeader+0xd9ffffea0cb55d5230 fffff80175af377c : 0000000000000000 0000000000000000 ffff0b1c13840aa2 0000000001000000 : nt!MiValidateSectionCreate+0x438ffffea0cb55d5410 fffff80175a58862 : ffffea0cb55d5740 0000000000000000 0000000000000000 0000000000000000 : nt!MiValidateSectionSigningPolicy+0xacffffea0cb55d5470 fffff80175af59eb : ffffa10bddf85650 ffffea0cb55d5740 ffffea0cb55d5740 ffffa10bd7bba0c0 : nt!MiCreateNewSection+0x59affffea0cb55d55d0 fffff80175af5034 : ffffea0cb55d5600 ffff8b0a2c1556c0 ffffa10bddf85650 0000000000000000 : nt!MiCreateImageOrDataSection+0x2dbffffea0cb55d56c0 fffff80175af4e17 : 0000000001000000 ffffea0cb55d5a80 0000000000000001 0000000000000010 : nt!MiCreateSection+0xf4ffffea0cb55d5840 fffff80175af4bfc : 0000004976b0ceb8 000000000000000d 0000000000000000 0000000000000001 : nt!MiCreateSectionCommon+0x207ffffea0cb55d5920 fffff8017580d8f5 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!NtCreateSection+0x5cffffea0cb55d5990 00007ffca02eda04 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiSystemServiceCopyEnd+0x250000004976b0ce68 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x00007ffc`a02eda04SYMBOL_NAME: CI!SymCryptSha1AppendBlocks+2c5MODULE_NAME: CIIMAGE_NAME: CI.dllIMAGE_VERSION: 10.0.19041.2546STACK_COMMAND: .cxr; .ecxr ; kbBUCKET_ID_FUNC_OFFSET: 2c5FAILURE_BUCKET_ID: 0x139_1d_INVALID_BALANCED_TREE_CI!SymCryptSha1AppendBlocksOSPLATFORM_TYPE: x64OSNAME: Windows 10FAILURE_ID_HASH: {e4d8144d-d224-3059-b55d-a345e7ee0e4e}Followup: MachineOwner
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Thanks for the clarification.
Since then, have you experienced another BSOD? Or your system has been working stably.
i got this error when i turn on the computer
then i saw there was a video card driver update
This minidump reports memory corruption. No drivers are mentioned.
You only sent one minidump. Did this error occur only once?
If it only happened once, maybe Windows was updating some driver in the background and caused the error.
See if the system will be stable or if it will give another BSOD. If it happens again, send the new minidump.
If the error occurred more than once, and you have more minidumps, send them.
Hi. I'm David, and I'm happy to help you.
Send the minidump files.
These files are in "C:\Windows\Minidump".
Copy any files you have to your desktop and store them in a ZIP file. Then upload the ZIP file to the cloud (OneDrive, Google Drive, Dropbox, etc...), choose to share it, and get the link.
Post the link to the ZIP file here so I can have a look.