Share via

BUGCHECK_CODE: 139

Anonymous
2022-08-10T04:22:47+00:00

computer has been crashing a couple of times, this is the first mini dump I looked at. other minidumps https://drive.google.com/drive/folders/1FQwCVgekQjNnsDZvFcGNKkX514G7PxsU?usp=sharing

*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure.  The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 000000000000001e, Type of memory safety violation
Arg2: fffffe036f771e10, Address of the trap frame for the exception that caused the BugCheck
Arg3: fffffe036f771d68, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1999

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 2457

    Key  : Analysis.Init.CPU.mSec
    Value: 624

    Key  : Analysis.Init.Elapsed.mSec
    Value: 69610

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 93

    Key  : Bugcheck.Code.DumpHeader
    Value: 0x139

    Key  : Bugcheck.Code.Register
    Value: 0x139

    Key  : Dump.Attributes.AsUlong
    Value: 8

    Key  : Dump.Attributes.KernelGeneratedTriageDump
    Value: 1

    Key  : FailFast.Name
    Value: INVALID_NEXT_THREAD

    Key  : FailFast.Type
    Value: 30

FILE_IN_CAB:  080922-7625-01.dmp

DUMP_FILE_ATTRIBUTES: 0x8
  Kernel Generated Triage Dump

BUGCHECK_CODE:  139

BUGCHECK_P1: 1e

BUGCHECK_P2: fffffe036f771e10

BUGCHECK_P3: fffffe036f771d68

BUGCHECK_P4: 0

IMAGE_NAME:  ntkrnlmp.exe

MODULE_NAME: ntkrnlmp

FAULTING_MODULE: fffff80060c00000 nt

TRAP_FRAME:  fffffe036f771e10 -- (.trap 0xfffffe036f771e10)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000000000000a rbx=0000000000000000 rcx=000000000000001e
rdx=fffff800618fdcc0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8006102f631 rsp=fffffe036f771fa0 rbp=ffffb981edb00180
 r8=0000000000000000  r9=fffffe036f772330 r10=0000000000000000
r11=0000000000000015 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
nt!KeQueryValuesThread+0x1e7001:
fffff800`6102f631 cd29            int     29h
Resetting default scope

EXCEPTION_RECORD:  fffffe036f771d68 -- (.exr 0xfffffe036f771d68)
ExceptionAddress: fffff8006102f631 (nt!KeQueryValuesThread+0x00000000001e7001)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 000000000000001e
Subcode: 0x1e FAST_FAIL_INVALID_NEXT_THREAD 

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  WmiPrvSE.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  000000000000001e

EXCEPTION_STR:  0xc0000409

STACK_TEXT:  
fffffe03`6f771ae8 fffff800`6100a569     : 00000000`00000139 00000000`0000001e fffffe03`6f771e10 fffffe03`6f771d68 : nt!KeBugCheckEx
fffffe03`6f771af0 fffff800`6100a990     : ffffb981`ecff7340 00000000`000d9900 00000000`00000001 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffffe03`6f771c30 fffff800`61008d23     : 00000220`7715d700 00000000`00000000 fffffe03`6f771f40 00000000`00000080 : nt!KiFastFailDispatch+0xd0
fffffe03`6f771e10 fffff800`6102f631     : ffffa507`31016580 00800090`00000090 00000000`00000000 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323
fffffe03`6f771fa0 fffff800`61216391     : ffffa507`00000000 fffffe03`00000000 00000000`00000000 00000000`00000000 : nt!KeQueryValuesThread+0x1e7001
fffffe03`6f772020 fffff800`61216022     : ffffa507`4f1ce660 ffffa507`4f1ce8e0 ffffa507`4fbdb080 00000000`00000001 : nt!PsQueryStatisticsProcess+0x111
fffffe03`6f7720a0 fffff800`611fc241     : 00000000`00000001 ffffa507`4f1ce080 00000000`ffffffff 00000000`00000000 : nt!ExpCopyProcessInfo+0x42
fffffe03`6f772120 fffff800`612721f7     : 0000004a`fbafc898 00000000`0007a000 00000000`00000030 00000000`00000000 : nt!ExpGetProcessInformation+0x9f1
fffffe03`6f772780 fffff800`612713a7     : ffffa507`4fbdb080 00000000`00000000 00000000`00000000 0000004a`fbafcc88 : nt!ExpQuerySystemInformation+0xd07
fffffe03`6f772ac0 fffff800`61009fb8     : ffffa507`4fbd0000 ffffa507`00000000 fffffe03`6f772b18 ffffffff`fb3b4c00 : nt!NtQuerySystemInformation+0x37
fffffe03`6f772b00 00007ffb`35dad604     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000004a`fbafc7f8 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`35dad604

IMAGE_VERSION:  10.0.19041.1826

STACK_COMMAND:  .cxr; .ecxr ; kb

FAILURE_BUCKET_ID:  0x139_1e_INVALID_NEXT_THREAD_IMAGE_ntkrnlmp.exe

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {64929928-a824-2134-285e-71128496d311}
Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Sumit D - IA 170.7K Reputation points Independent Advisor
    2022-08-10T04:56:19+00:00

    Hi,

    I am Sumit here to assist you with this question.

    We need log files(called dump files) that tell us what lead to crash.

    Please share them with us for a better analysis of the problem. Instructions can be found here:

    https://answers.microsoft.com/en-us/windows/for...

    To share files here, please see:

    How to share diagnostic files/logs on Microsoft community

    https://answers.microsoft.com/en-us/feedback/fo...

    Was this answer helpful?

    0 comments No comments