5: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffc3857dcd41b0, memory referenced.
Arg2: 0000000000000000, X64: bit 0 set if the fault was due to a not-present PTE.
bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the processor decided the fault was due to a corrupted PTE.
bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
- ARM64: bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: fffff80381a13dbf, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Type
Value: Read
Key : Analysis.CPU.mSec
Value: 5327
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 6609
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 405
Key : Analysis.Init.Elapsed.mSec
Value: 7771
Key : Analysis.Memory.CommitPeak.Mb
Value: 86
Key : Bugcheck.Code.DumpHeader
Value: 0x50
Key : Bugcheck.Code.Register
Value: 0x50
Key : Dump.Attributes.AsUlong
Value: 8
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
FILE_IN_CAB: 042223-21937-01.dmp
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
BUGCHECK_CODE: 50
BUGCHECK_P1: ffffc3857dcd41b0
BUGCHECK_P2: 0
BUGCHECK_P3: fffff80381a13dbf
BUGCHECK_P4: 2
READ_ADDRESS: fffff803820fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
ffffc3857dcd41b0
MM_INTERNAL_CODE: 2
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: WmiPrvSE.exe
TRAP_FRAME: ffffb203508f5d20 -- (.trap 0xffffb203508f5d20)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffd38556d02000 rbx=0000000000000000 rcx=ffffc3857dcd41b0
rdx=ffffd38556d04688 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80381a13dbf rsp=ffffb203508f5eb0 rbp=ffffd3856deae580
r8=ffffb203508f5ec0 r9=0000000000000003 r10=7ffffffffffffffc
r11=000000000000005a r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!CmpPerformSingleKcbCacheLookup+0x20f:
fffff803`81a13dbf 8b01 mov eax,dword ptr [rcx] ds:ffffc385`7dcd41b0=????????
Resetting default scope
LOCK_ADDRESS: fffff80382044c60 -- (!locks fffff80382044c60)
Cannot get _ERESOURCE type
Resource @ nt!PiEngineLock (0xfffff80382044c60) Available
1 total locks
PNP_TRIAGE_DATA:
Lock address : 0xfffff80382044c60
Thread Count : 0
Thread address: 0x0000000000000000
Thread wait : 0x0
STACK_TEXT:
ffffb203`508f5a78 fffff803`8184ab53 : 00000000`00000050 ffffc385`7dcd41b0 00000000`00000000 ffffb203`508f5d20 : nt!KeBugCheckEx
ffffb203`508f5a80 fffff803`8166e7b0 : ffffb203`508f5bd8 00000000`00000000 ffffb203`508f5da0 00000000`00000000 : nt!MiSystemFault+0x1b2173
ffffb203`508f5b80 fffff803`8180b6d8 : ffffd385`56405600 ffffb203`00000110 ffffb203`00000100 00000000`00000000 : nt!MmAccessFault+0x400
ffffb203`508f5d20 fffff803`81a13dbf : ffffd385`5a5d2853 fffff803`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x358
ffffb203`508f5eb0 fffff803`81a1c4d7 : ffffd385`8e9048f0 ffffd385`56d31450 ffffb203`508f60d0 fffff803`00000003 : nt!CmpPerformSingleKcbCacheLookup+0x20f
ffffb203`508f5f40 fffff803`81a19eca : 00000000`00000000 ffffb203`508f6000 ffffb203`00000003 00000000`00000000 : nt!CmpPerformCompleteKcbCacheLookup+0x77
ffffb203`508f5fd0 fffff803`81a19953 : 00000000`0000001c ffffb203`508f6320 ffffb203`508f62d8 ffff8d8f`645df620 : nt!CmpDoParseKey+0x2da
ffffb203`508f6270 fffff803`81a1501e : fffff803`81a19601 00000000`00000000 ffff8d8f`645df620 ffffb203`508f6400 : nt!CmpParseKey+0x2c3
ffffb203`508f6410 fffff803`81a0ccea : ffff8d8f`645df600 ffffb203`508f6678 ffff8d8f`00000240 ffff8d8f`4c581140 : nt!ObpLookupObjectName+0x3fe
ffffb203`508f65e0 fffff803`81a0cacc : 00000000`00000000 00000000`00000000 00000000`00000000 ffff8d8f`4c581140 : nt!ObOpenObjectByNameEx+0x1fa
ffffb203`508f6710 fffff803`81a0c5e1 : ffffb203`508f6be0 ffffb203`508f6a80 00000000`00000000 00000000`00000000 : nt!ObOpenObjectByName+0x5c
ffffb203`508f6760 fffff803`81a0c30f : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmOpenKey+0x2c1
ffffb203`508f69c0 fffff803`8180f3f5 : 00000000`00000000 00000000`00000000 ffffa50e`60c1b699 00000000`00000000 : nt!NtOpenKeyEx+0xf
ffffb203`508f6a00 fffff803`818007f0 : fffff803`81a6db7a 00000000`00000004 ffffd385`8f07a870 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
ffffb203`508f6b98 fffff803`81a6db7a : 00000000`00000004 ffffd385`8f07a870 00000000`00000000 00000000`00000010 : nt!KiServiceLinkage
ffffb203`508f6ba0 fffff803`81a6daaa : 00000000`00000000 ffffffff`80000144 ffffd385`89c08a1c ffffd385`89c08a1c : nt!_RegRtlOpenKeyTransacted+0xba
ffffb203`508f6c40 fffff803`81a704ad : 00000000`000000cc ffffb203`508f6d00 00000000`00000100 00000000`00000000 : nt!SysCtxRegOpenKey+0x3a
ffffb203`508f6c80 fffff803`81a6d68b : 00000000`00000000 ffffd385`8f07a870 fffff803`00000080 00000000`00000000 : nt!_CmOpenDeviceRegKeyWorker+0x1b9
ffffb203`508f6d40 fffff803`81a6b9fe : 00000000`00000000 ffffb203`508f6ea0 ffffb203`508f70d8 00000000`00000000 : nt!_CmOpenDeviceRegKey+0xef
ffffb203`508f6da0 fffff803`81a6b87b : 00000000`00000002 fffff803`81a3f937 ffffb203`508f7001 ffffb203`508f7050 : nt!_CmGetDeviceRegPropWorker+0x102
ffffb203`508f6ef0 fffff803`81acd680 : 00000000`00000000 ffffb203`508f7059 00000000`00000802 ffffb203`00000000 : nt!_CmGetDeviceRegProp+0xff
ffffb203`508f7000 fffff803`81a3cbd6 : ffffb203`508f7218 000000fa`d477cae0 00000000`00000038 00000000`00000816 : nt!PiCMGetRegistryProperty+0x12c
ffffb203`508f70b0 fffff803`81a3ca63 : ffffb203`508f71f8 00000000`00000003 00000000`0000026c fffff803`81a118ee : nt!PiCMHandleIoctl+0x156
ffffb203`508f70f0 fffff803`81ac275a : 00000000`00000000 fffff803`81ac26f0 00000000`00000000 fffff803`8161eaba : nt!PiCMFastIoDeviceDispatch+0x53
ffffb203`508f7140 fffff803`81a10206 : 00000000`0000026c 00000000`00000000 00000000`00000000 ffff8d8f`5f883d10 : nt!PiDaFastIoDispatch+0x6a
ffffb203`508f71a0 fffff803`81a0fae6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x706
ffffb203`508f72e0 fffff803`8180f3f5 : 00000000`00000000 ffffb203`508f7440 ffff8d8f`8c3d5640 ffff8d8f`5f5ca1c0 : nt!NtDeviceIoControlFile+0x56
ffffb203`508f7350 00007ff8`c94ad144 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
000000fa`d477c9d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`c94ad144
SYMBOL_NAME: nt!CmpPerformSingleKcbCacheLookup+20f
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.2846
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 20f
FAILURE_BUCKET_ID: AV_R_(null)_nt!CmpPerformSingleKcbCacheLookup
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {c86774e7-4096-71d8-0e68-cfea33dbf19d}
Followup: MachineOwner
---------
5: kd> kb ffffb203508f5d20
Requested number of stack frames (0xfffb203508f5d20) is too large! The maximum number is 0xffff.
^ Range error in 'kb ffffb203508f5d20'
5: kd> kb
# RetAddr : Args to Child : Call Site
00 fffff803`8184ab53 : 00000000`00000050 ffffc385`7dcd41b0 00000000`00000000 ffffb203`508f5d20 : nt!KeBugCheckEx
01 fffff803`8166e7b0 : ffffb203`508f5bd8 00000000`00000000 ffffb203`508f5da0 00000000`00000000 : nt!MiSystemFault+0x1b2173
02 fffff803`8180b6d8 : ffffd385`56405600 ffffb203`00000110 ffffb203`00000100 00000000`00000000 : nt!MmAccessFault+0x400
03 fffff803`81a13dbf : ffffd385`5a5d2853 fffff803`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x358
04 fffff803`81a1c4d7 : ffffd385`8e9048f0 ffffd385`56d31450 ffffb203`508f60d0 fffff803`00000003 : nt!CmpPerformSingleKcbCacheLookup+0x20f
05 fffff803`81a19eca : 00000000`00000000 ffffb203`508f6000 ffffb203`00000003 00000000`00000000 : nt!CmpPerformCompleteKcbCacheLookup+0x77
06 fffff803`81a19953 : 00000000`0000001c ffffb203`508f6320 ffffb203`508f62d8 ffff8d8f`645df620 : nt!CmpDoParseKey+0x2da
07 fffff803`81a1501e : fffff803`81a19601 00000000`00000000 ffff8d8f`645df620 ffffb203`508f6400 : nt!CmpParseKey+0x2c3
08 fffff803`81a0ccea : ffff8d8f`645df600 ffffb203`508f6678 ffff8d8f`00000240 ffff8d8f`4c581140 : nt!ObpLookupObjectName+0x3fe
09 fffff803`81a0cacc : 00000000`00000000 00000000`00000000 00000000`00000000 ffff8d8f`4c581140 : nt!ObOpenObjectByNameEx+0x1fa
0a fffff803`81a0c5e1 : ffffb203`508f6be0 ffffb203`508f6a80 00000000`00000000 00000000`00000000 : nt!ObOpenObjectByName+0x5c
0b fffff803`81a0c30f : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmOpenKey+0x2c1
0c fffff803`8180f3f5 : 00000000`00000000 00000000`00000000 ffffa50e`60c1b699 00000000`00000000 : nt!NtOpenKeyEx+0xf
0d fffff803`818007f0 : fffff803`81a6db7a 00000000`00000004 ffffd385`8f07a870 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
0e fffff803`81a6db7a : 00000000`00000004 ffffd385`8f07a870 00000000`00000000 00000000`00000010 : nt!KiServiceLinkage
0f fffff803`81a6daaa : 00000000`00000000 ffffffff`80000144 ffffd385`89c08a1c ffffd385`89c08a1c : nt!_RegRtlOpenKeyTransacted+0xba
10 fffff803`81a704ad : 00000000`000000cc ffffb203`508f6d00 00000000`00000100 00000000`00000000 : nt!SysCtxRegOpenKey+0x3a
11 fffff803`81a6d68b : 00000000`00000000 ffffd385`8f07a870 fffff803`00000080 00000000`00000000 : nt!_CmOpenDeviceRegKeyWorker+0x1b9
12 fffff803`81a6b9fe : 00000000`00000000 ffffb203`508f6ea0 ffffb203`508f70d8 00000000`00000000 : nt!_CmOpenDeviceRegKey+0xef
13 fffff803`81a6b87b : 00000000`00000002 fffff803`81a3f937 ffffb203`508f7001 ffffb203`508f7050 : nt!_CmGetDeviceRegPropWorker+0x102
14 fffff803`81acd680 : 00000000`00000000 ffffb203`508f7059 00000000`00000802 ffffb203`00000000 : nt!_CmGetDeviceRegProp+0xff
15 fffff803`81a3cbd6 : ffffb203`508f7218 000000fa`d477cae0 00000000`00000038 00000000`00000816 : nt!PiCMGetRegistryProperty+0x12c
16 fffff803`81a3ca63 : ffffb203`508f71f8 00000000`00000003 00000000`0000026c fffff803`81a118ee : nt!PiCMHandleIoctl+0x156
17 fffff803`81ac275a : 00000000`00000000 fffff803`81ac26f0 00000000`00000000 fffff803`8161eaba : nt!PiCMFastIoDeviceDispatch+0x53
18 fffff803`81a10206 : 00000000`0000026c 00000000`00000000 00000000`00000000 ffff8d8f`5f883d10 : nt!PiDaFastIoDispatch+0x6a
19 fffff803`81a0fae6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x706
1a fffff803`8180f3f5 : 00000000`00000000 ffffb203`508f7440 ffff8d8f`8c3d5640 ffff8d8f`5f5ca1c0 : nt!NtDeviceIoControlFile+0x56
1b 00007ff8`c94ad144 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
1c 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`c94ad144
5: kd> db ffffc3857dcd41b0
ffffc385`7dcd41b0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
ffffc385`7dcd41c0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
ffffc385`7dcd41d0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
ffffc385`7dcd41e0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
ffffc385`7dcd41f0 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
ffffc385`7dcd4200 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
ffffc385`7dcd4210 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
ffffc385`7dcd4220 ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ?? ????????????????
5: kd> db fffff80381a13dbf
fffff803`81a13dbf 8b 01 48 8d 71 1a a8 01-0f 84 2e 03 00 00 45 0f ..H.q.........E.
fffff803`81a13dcf b7 17 66 41 d1 ea 49 8b-7f 08 44 0f b7 49 18 74 ..fA..I...D..I.t
fffff803`81a13ddf 49 66 45 85 c9 74 43 0f-b7 07 48 83 c7 02 44 0f IfE..tC...H...D.
fffff803`81a13def b6 1e 48 ff c6 66 41 3b-c3 74 20 66 83 f8 61 72 ..H..fA;.t f..ar
fffff803`81a13dff 12 66 83 f8 7a 0f 87 83-16 1e 00 b9 e0 ff 00 00 .f..z...........
fffff803`81a13e0f 66 03 c1 0f b7 d0 41 2b-d3 75 19 b8 ff ff 00 00 f.....A+.u......
fffff803`81a13e1f 66 44 03 c8 66 44 03 d0-75 b7 41 0f b7 c1 41 0f fD..fD..u.A...A.
fffff803`81a13e2f b7 d2 2b d0 85 d2 0f 85-60 16 1e 00 4d 85 f6 0f ..+.....`...M...
5: kd> !address fffff80381a13dbf
Mapping user range ...
ERROR: !address: extension exception 0x80004005.
"ExtRemoteTyped::Set from type and offset"
5: kd> u fffff80381a13dbf
nt!CmpPerformSingleKcbCacheLookup+0x20f:
fffff803`81a13dbf 8b01 mov eax,dword ptr [rcx]
fffff803`81a13dc1 488d711a lea rsi,[rcx+1Ah]
fffff803`81a13dc5 a801 test al,1
fffff803`81a13dc7 0f842e030000 je nt!CmpPerformSingleKcbCacheLookup+0x54b (fffff803`81a140fb)
fffff803`81a13dcd 450fb717 movzx r10d,word ptr [r15]
fffff803`81a13dd1 6641d1ea shr r10w,1
fffff803`81a13dd5 498b7f08 mov rdi,qword ptr [r15+8]
fffff803`81a13dd9 440fb74918 movzx r9d,word ptr [rcx+18h]
5: kd> ub
nt!CmpPerformSingleKcbCacheLookup+0x20f:
fffff803`81a13dbf 8b01 mov eax,dword ptr [rcx]
fffff803`81a13dc1 488d711a lea rsi,[rcx+1Ah]
fffff803`81a13dc5 a801 test al,1
fffff803`81a13dc7 0f842e030000 je nt!CmpPerformSingleKcbCacheLookup+0x54b (fffff803`81a140fb)
fffff803`81a13dcd 450fb717 movzx r10d,word ptr [r15]
fffff803`81a13dd1 6641d1ea shr r10w,1
fffff803`81a13dd5 498b7f08 mov rdi,qword ptr [r15+8]
fffff803`81a13dd9 440fb74918 movzx r9d,word ptr [rcx+18h]
5: kd> r
rax=0000000000000000 rbx=ffffc3857dcd41b0 rcx=0000000000000050
rdx=ffffc3857dcd41b0 rsi=0000000000000000 rdi=ffffb203508f5c40
rip=fffff803817fbc10 rsp=ffffb203508f5a78 rbp=ffff8d8f8c3d5640
r8=0000000000000000 r9=ffffb203508f5d20 r10=fffff8038204f2c0
r11=ffffb203508f59f8 r12=0000000000000000 r13=ffff800000000000
r14=ffffc3857dcd41b0 r15=fffff8038204f2c0
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00040246
nt!KeBugCheckEx:
fffff803`817fbc10 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffb203`508f5a80=0000000000000050
5: kd> !pte fffff803817fbc10
VA fffff803817fbc10
PXE at FFFFFEFF7FBFDF80 PPE at FFFFFEFF7FBF0070 PDE at FFFFFEFF7E00E058 PTE at FFFFFEFC01C0BFD8
contains 0000000005409063 contains 0000000005519063 contains 0A000000036001A1 contains 0000000000000000
pfn 5409 ---DA--KWEV pfn 5519 ---DA--KWEV pfn 3600 -GL-A--KREV LARGE PAGE pfn 37fb
5: kd> !pool fffff803817fbc10
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
HeapDbgInitExtension Failed