Skip to content

KERNEL_MODE_HEAP_CORRUPTION #97

@cdwenwang

Description

@cdwenwang

nt!KeBugCheckEx:
fffff806dcab8460 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffff68eb8c36960=000000000000013a
42: kd> !analyze -v


  •                                                                         *
    
  •                    Bugcheck Analysis                                    *
    
  •                                                                         *
    

KERNEL_MODE_HEAP_CORRUPTION (13a)
The kernel mode heap manager has detected corruption in a heap.
Arguments:
Arg1: 0000000000000012, Type of corruption detected
Arg2: ffffbd0455200140, Address of the heap that reported the corruption
Arg3: ffffbd04a1ca7000, Address at which the corruption was detected
Arg4: 0000000000000000

Debugging Details:

KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec
Value: 2796

Key  : Analysis.Elapsed.mSec
Value: 7765

Key  : Analysis.IO.Other.Mb
Value: 3

Key  : Analysis.IO.Read.Mb
Value: 1

Key  : Analysis.IO.Write.Mb
Value: 27

Key  : Analysis.Init.CPU.mSec
Value: 671

Key  : Analysis.Init.Elapsed.mSec
Value: 60844

Key  : Analysis.Memory.CommitPeak.Mb
Value: 117

Key  : Analysis.Version.DbgEng
Value: 10.0.27793.1000

Key  : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre

Key  : Analysis.Version.Ext
Value: 1.2410.2.2

Key  : Bugcheck.Code.KiBugCheckData
Value: 0x13a

Key  : Bugcheck.Code.LegacyAPI
Value: 0x13a

Key  : Bugcheck.Code.TargetModel
Value: 0x13a

Key  : Dump.Attributes.AsUlong
Value: 0x20000

Key  : Failure.Bucket
Value: 0x13a_12_aehd!unknown_function

Key  : Failure.Exception.IP.Address
Value: 0xfffff806dd1360d1

Key  : Failure.Exception.IP.Module
Value: nt

Key  : Failure.Exception.IP.Offset
Value: 0xb360d1

Key  : Failure.Hash
Value: {82c1293b-3885-dccd-3da2-3efe698d1a48}

Key  : Hypervisor.Enlightenments.Value
Value: 0

Key  : Hypervisor.Enlightenments.ValueHex
Value: 0x0

Key  : Hypervisor.Flags.AnyHypervisorPresent
Value: 0

Key  : Hypervisor.Flags.ApicEnlightened
Value: 0

Key  : Hypervisor.Flags.ApicVirtualizationAvailable
Value: 1

Key  : Hypervisor.Flags.AsyncMemoryHint
Value: 0

Key  : Hypervisor.Flags.CoreSchedulerRequested
Value: 0

Key  : Hypervisor.Flags.CpuManager
Value: 0

Key  : Hypervisor.Flags.DeprecateAutoEoi
Value: 0

Key  : Hypervisor.Flags.DynamicCpuDisabled
Value: 0

Key  : Hypervisor.Flags.Epf
Value: 0

Key  : Hypervisor.Flags.ExtendedProcessorMasks
Value: 0

Key  : Hypervisor.Flags.HardwareMbecAvailable
Value: 1

Key  : Hypervisor.Flags.MaxBankNumber
Value: 0

Key  : Hypervisor.Flags.MemoryZeroingControl
Value: 0

Key  : Hypervisor.Flags.NoExtendedRangeFlush
Value: 0

Key  : Hypervisor.Flags.NoNonArchCoreSharing
Value: 0

Key  : Hypervisor.Flags.Phase0InitDone
Value: 0

Key  : Hypervisor.Flags.PowerSchedulerQos
Value: 0

Key  : Hypervisor.Flags.RootScheduler
Value: 0

Key  : Hypervisor.Flags.SynicAvailable
Value: 0

Key  : Hypervisor.Flags.UseQpcBias
Value: 0

Key  : Hypervisor.Flags.Value
Value: 16908288

Key  : Hypervisor.Flags.ValueHex
Value: 0x1020000

Key  : Hypervisor.Flags.VpAssistPage
Value: 0

Key  : Hypervisor.Flags.VsmAvailable
Value: 0

Key  : Hypervisor.RootFlags.AccessStats
Value: 0

Key  : Hypervisor.RootFlags.CrashdumpEnlightened
Value: 0

Key  : Hypervisor.RootFlags.CreateVirtualProcessor
Value: 0

Key  : Hypervisor.RootFlags.DisableHyperthreading
Value: 0

Key  : Hypervisor.RootFlags.HostTimelineSync
Value: 0

Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
Value: 0

Key  : Hypervisor.RootFlags.IsHyperV
Value: 0

Key  : Hypervisor.RootFlags.LivedumpEnlightened
Value: 0

Key  : Hypervisor.RootFlags.MapDeviceInterrupt
Value: 0

Key  : Hypervisor.RootFlags.MceEnlightened
Value: 0

Key  : Hypervisor.RootFlags.Nested
Value: 0

Key  : Hypervisor.RootFlags.StartLogicalProcessor
Value: 0

Key  : Hypervisor.RootFlags.Value
Value: 0

Key  : Hypervisor.RootFlags.ValueHex
Value: 0x0

Key  : SecureKernel.HalpHvciEnabled
Value: 0

Key  : WER.OS.Branch
Value: ge_release

Key  : WER.OS.Version
Value: 10.0.26100.1

BUGCHECK_CODE: 13a

BUGCHECK_P1: 12

BUGCHECK_P2: ffffbd0455200140

BUGCHECK_P3: ffffbd04a1ca7000

BUGCHECK_P4: 0

FILE_IN_CAB: MEMORY.DMP

DUMP_FILE_ATTRIBUTES: 0x20000

FAULTING_THREAD: ffffbd0484ef8080

CORRUPTING_POOL_ADDRESS: ffffbd04a1ca7000 Nonpaged pool

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXWINLOGON: 1

PROCESS_NAME: qemu-system-x86_64.exe

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions