- ************* Preparing the environment for Debugger Extensions Gallery repositories **************
 - ExtensionRepository : Implicit
 - UseExperimentalFeatureForNugetShare : true
 - AllowNugetExeUpdate : true
 - NonInteractiveNuget : true
 - AllowNugetMSCredentialProviderInstall : true
 - AllowParallelInitializationOfLocalRepositories : true
 - EnableRedirectToV8JsProvider : false
 - -- Configuring repositories
 - ----> Repository : LocalInstalled, Enabled: true
 - ----> Repository : UserExtensions, Enabled: true
 - >>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
 - ************* Waiting for Debugger Extensions Gallery to Initialize **************
 - >>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.047 seconds
 - ----> Repository : UserExtensions, Enabled: true, Packages count: 0
 - ----> Repository : LocalInstalled, Enabled: true, Packages count: 41
 - Microsoft (R) Windows Debugger Version 10.0.27553.1004 AMD64
 - Copyright (c) Microsoft Corporation. All rights reserved.
 - Loading Dump File [C:\Windows\MEMORY.DMP]
 - Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
 - ************* Path validation summary **************
 - Response Time (ms) Location
 - Deferred srv*
 - Symbol search path is: srv*
 - Executable search path is:
 - Windows 10 Kernel Version 19041 MP (8 procs) Free x64
 - Product: WinNt, suite: TerminalServer SingleUserTS
 - Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
 - Kernel base = 0xfffff800`42000000 PsLoadedModuleList = 0xfffff800`42c2a820
 - Debug session time: Fri Jul 19 02:35:42.990 2024 (UTC + 2:00)
 - System Uptime: 0 days 8:16:25.224
 - Loading Kernel Symbols
 - ...............................................................
 - ................................................................
 - ................................................................
 - .....
 - Loading User Symbols
 - Loading unloaded module list
 - .......
 - For analysis of this file, run !analyze -v
 - nt!KeBugCheckEx:
 - fffff800`423fdde0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffeb89`522c3550=0000000000000139
 - 2: kd> !analyze -v
 - *******************************************************************************
 - * *
 - * Bugcheck Analysis *
 - * *
 - *******************************************************************************
 - KERNEL_SECURITY_CHECK_FAILURE (139)
 - A kernel component has corrupted a critical data structure. The corruption
 - could potentially allow a malicious user to gain control of this machine.
 - Arguments:
 - Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
 - Arg2: ffffeb89522c3870, Address of the trap frame for the exception that caused the BugCheck
 - Arg3: ffffeb89522c37c8, Address of the exception record for the exception that caused the BugCheck
 - Arg4: 0000000000000000, Reserved
 - Debugging Details:
 - ------------------
 - Unable to load image \SystemRoot\system32\DRIVERS\nfs41_driver.sys, Win32 error 0n2
 - KEY_VALUES_STRING: 1
 - Key : Analysis.CPU.mSec
 - Value: 4140
 - Key : Analysis.Elapsed.mSec
 - Value: 4656
 - Key : Analysis.IO.Other.Mb
 - Value: 0
 - Key : Analysis.IO.Read.Mb
 - Value: 1
 - Key : Analysis.IO.Write.Mb
 - Value: 0
 - Key : Analysis.Init.CPU.mSec
 - Value: 858
 - Key : Analysis.Init.Elapsed.mSec
 - Value: 136137
 - Key : Analysis.Memory.CommitPeak.Mb
 - Value: 91
 - Key : Bugcheck.Code.KiBugCheckData
 - Value: 0x139
 - Key : Bugcheck.Code.LegacyAPI
 - Value: 0x139
 - Key : Bugcheck.Code.TargetModel
 - Value: 0x139
 - Key : FailFast.Name
 - Value: CORRUPT_LIST_ENTRY
 - Key : FailFast.Type
 - Value: 3
 - Key : Failure.Bucket
 - Value: 0x139_3_CORRUPT_LIST_ENTRY_nfs41_driver!RtlFailFast
 - Key : Failure.Hash
 - Value: {7fe0db02-499d-ef29-7ce7-92b961f8dd2f}
 - Key : Hypervisor.Enlightenments.Value
 - Value: 12576
 - Key : Hypervisor.Enlightenments.ValueHex
 - Value: 3120
 - Key : Hypervisor.Flags.AnyHypervisorPresent
 - Value: 1
 - Key : Hypervisor.Flags.ApicEnlightened
 - Value: 0
 - Key : Hypervisor.Flags.ApicVirtualizationAvailable
 - Value: 0
 - Key : Hypervisor.Flags.AsyncMemoryHint
 - Value: 0
 - Key : Hypervisor.Flags.CoreSchedulerRequested
 - Value: 0
 - Key : Hypervisor.Flags.CpuManager
 - Value: 0
 - Key : Hypervisor.Flags.DeprecateAutoEoi
 - Value: 1
 - Key : Hypervisor.Flags.DynamicCpuDisabled
 - Value: 0
 - Key : Hypervisor.Flags.Epf
 - Value: 0
 - Key : Hypervisor.Flags.ExtendedProcessorMasks
 - Value: 0
 - Key : Hypervisor.Flags.HardwareMbecAvailable
 - Value: 0
 - Key : Hypervisor.Flags.MaxBankNumber
 - Value: 0
 - Key : Hypervisor.Flags.MemoryZeroingControl
 - Value: 0
 - Key : Hypervisor.Flags.NoExtendedRangeFlush
 - Value: 1
 - Key : Hypervisor.Flags.NoNonArchCoreSharing
 - Value: 0
 - Key : Hypervisor.Flags.Phase0InitDone
 - Value: 1
 - Key : Hypervisor.Flags.PowerSchedulerQos
 - Value: 0
 - Key : Hypervisor.Flags.RootScheduler
 - Value: 0
 - Key : Hypervisor.Flags.SynicAvailable
 - Value: 1
 - Key : Hypervisor.Flags.UseQpcBias
 - Value: 0
 - Key : Hypervisor.Flags.Value
 - Value: 536632
 - Key : Hypervisor.Flags.ValueHex
 - Value: 83038
 - Key : Hypervisor.Flags.VpAssistPage
 - Value: 1
 - Key : Hypervisor.Flags.VsmAvailable
 - Value: 0
 - Key : Hypervisor.RootFlags.AccessStats
 - Value: 0
 - Key : Hypervisor.RootFlags.CrashdumpEnlightened
 - Value: 0
 - Key : Hypervisor.RootFlags.CreateVirtualProcessor
 - Value: 0
 - Key : Hypervisor.RootFlags.DisableHyperthreading
 - Value: 0
 - Key : Hypervisor.RootFlags.HostTimelineSync
 - Value: 0
 - Key : Hypervisor.RootFlags.HypervisorDebuggingEnabled
 - Value: 0
 - Key : Hypervisor.RootFlags.IsHyperV
 - Value: 0
 - Key : Hypervisor.RootFlags.LivedumpEnlightened
 - Value: 0
 - Key : Hypervisor.RootFlags.MapDeviceInterrupt
 - Value: 0
 - Key : Hypervisor.RootFlags.MceEnlightened
 - Value: 0
 - Key : Hypervisor.RootFlags.Nested
 - Value: 0
 - Key : Hypervisor.RootFlags.StartLogicalProcessor
 - Value: 0
 - Key : Hypervisor.RootFlags.Value
 - Value: 0
 - Key : Hypervisor.RootFlags.ValueHex
 - Value: 0
 - Key : SecureKernel.HalpHvciEnabled
 - Value: 0
 - Key : WER.OS.Branch
 - Value: vb_release
 - Key : WER.OS.Version
 - Value: 10.0.19041.1
 - BUGCHECK_CODE: 139
 - BUGCHECK_P1: 3
 - BUGCHECK_P2: ffffeb89522c3870
 - BUGCHECK_P3: ffffeb89522c37c8
 - BUGCHECK_P4: 0
 - FILE_IN_CAB: MEMORY.DMP
 - TRAP_FRAME: ffffeb89522c3870 -- (.trap 0xffffeb89522c3870)
 - NOTE: The trap frame does not contain all registers.
 - Some register values may be zeroed or incorrect.
 - rax=0000000000000003 rbx=0000000000000000 rcx=0000000000000003
 - rdx=fffff80048cf6d60 rsi=0000000000000000 rdi=0000000000000000
 - rip=fffff80048cd4bba rsp=ffffeb89522c3a08 rbp=0000000000000080
 - r8=0000000000000000 r9=0000000000000659 r10=0000000075706361
 - r11=0000000000001001 r12=0000000000000000 r13=0000000000000000
 - r14=0000000000000000 r15=0000000000000000
 - iopl=0 nv up ei ng nz na pe nc
 - nfs41_driver!RtlFailFast+0xa:
 - fffff800`48cd4bba cd29 int 29h
 - Resetting default scope
 - EXCEPTION_RECORD: ffffeb89522c37c8 -- (.exr 0xffffeb89522c37c8)
 - ExceptionAddress: fffff80048cd4bba (nfs41_driver!RtlFailFast+0x000000000000000a)
 - ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
 - ExceptionFlags: 00000001
 - NumberParameters: 1
 - Parameter[0]: 0000000000000003
 - Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
 - BLACKBOXBSD: 1 (!blackboxbsd)
 - BLACKBOXNTFS: 1 (!blackboxntfs)
 - BLACKBOXWINLOGON: 1
 - PROCESS_NAME: System
 - ERROR_CODE: (NTSTATUS) 0xc0000409 - Das System hat in dieser Anwendung den berlauf eines stapelbasierten Puffers ermittelt. Dieser berlauf k nnte einem b sartigen Benutzer erm glichen, die Steuerung der Anwendung zu bernehmen.
 - EXCEPTION_CODE_STR: c0000409
 - EXCEPTION_PARAMETER1: 0000000000000003
 - EXCEPTION_STR: 0xc0000409
 - STACK_TEXT:
 - ffffeb89`522c3548 fffff800`424125a9 : 00000000`00000139 00000000`00000003 ffffeb89`522c3870 ffffeb89`522c37c8 : nt!KeBugCheckEx
 - ffffeb89`522c3550 fffff800`42412b50 : 00000000`00000000 00000000`00000000 ffffeb89`522c3790 00000000`00000000 : nt!KiBugCheckDispatch+0x69
 - ffffeb89`522c3690 fffff800`424109f2 : ffffda8b`05b9b080 fffff800`48cd6620 00000000`00000000 fffff800`48cf2e70 : nt!KiFastFailDispatch+0xd0
 - ffffeb89`522c3870 fffff800`48cd4bba : fffff800`48cd3e7d 00000000`00000003 fffff800`422353da 00000000`00000001 : nt!KiRaiseSecurityCheckFailure+0x332
 - ffffeb89`522c3a08 fffff800`48cd3e7d : 00000000`00000003 fffff800`422353da 00000000`00000001 00000000`75706361 : nfs41_driver!RtlFailFast+0xa [C:\Program Files (x86)\Windows Kits\10\Include\10.0.19041.0\km\wdm.h @ 11545]
 - ffffeb89`522c3a10 fffff800`48cd4c11 : fffff800`48cf6d60 fffff800`48cf6d60 00000000`00000000 fffff800`4223c243 : nfs41_driver!FatalListEntryError+0x1d [C:\Program Files (x86)\Windows Kits\10\Include\10.0.19041.0\km\wdm.h @ 11779]
 - ffffeb89`522c3a40 fffff800`48cd4248 : fffff800`48cf6d60 fffff800`48cd3e4e ffffda8b`0dd66b00 00000000`00000001 : nfs41_driver!RtlpCheckListEntry+0x51 [C:\Program Files (x86)\Windows Kits\10\Include\10.0.19041.0\km\wdm.h @ 11794]
 - ffffeb89`522c3a70 fffff800`48ce1d9d : fffff800`48cf6d60 ffffda8b`0dd66b38 fffff800`00000000 fffff800`00000000 : nfs41_driver!InsertTailList+0x18 [C:\Program Files (x86)\Windows Kits\10\Include\10.0.19041.0\km\wdm.h @ 11900]
 - ffffeb89`522c3ab0 fffff800`48cd6812 : ffffda8b`0dd66ae0 ffff9b00`00000032 00000200`124b2980 00000200`ba80d8a0 : nfs41_driver!nfs41_UpcallWaitForReply+0x3d [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41_driver.c @ 1645]
 - ffffeb89`522c3b30 fffff800`42348da5 : 00000000`00000000 fffff800`48cd6620 00000000`00000000 00078404`ad9b3dfe : nfs41_driver!fcbopen_main+0x1f2 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41_driver.c @ 7485]
 - ffffeb89`522c3c10 fffff800`42406de8 : ffffc400`ee526180 ffffda8b`05b9b080 fffff800`42348d50 001c99d8`001c99ca : nt!PspSystemThreadStartup+0x55
 - ffffeb89`522c3c60 00000000`00000000 : ffffeb89`522c4000 ffffeb89`522be000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
 - FAULTING_SOURCE_LINE: C:\Program Files (x86)\Windows Kits\10\Include\10.0.19041.0\km\wdm.h
 - FAULTING_SOURCE_FILE: C:\Program Files (x86)\Windows Kits\10\Include\10.0.19041.0\km\wdm.h
 - FAULTING_SOURCE_LINE_NUMBER: 11545
 - FAULTING_SOURCE_CODE:
 - 11541: )
 - 11542:
 - 11543: {
 - 11544:
 - >11545: __fastfail(Code);
 - 11546: }
 - 11547:
 - 11548: #endif // _MSC_VER
 - 11549:
 - 11550: //
 - SYMBOL_NAME: nfs41_driver!RtlFailFast+a
 - MODULE_NAME: nfs41_driver
 - IMAGE_NAME: nfs41_driver.sys
 - STACK_COMMAND: .cxr; .ecxr ; kb
 - BUCKET_ID_FUNC_OFFSET: a
 - FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_nfs41_driver!RtlFailFast
 - OS_VERSION: 10.0.19041.1
 - BUILDLAB_STR: vb_release
 - OSPLATFORM_TYPE: x64
 - OSNAME: Windows 10
 - FAILURE_ID_HASH: {7fe0db02-499d-ef29-7ce7-92b961f8dd2f}
 - Followup: MachineOwner
 - ---------
 
nfs41_driver.sys crash
Posted by Anonymous on Fri 19th Jul 2024 09:59
raw | new post
Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.
 nrubsig.kpaste.net RSS