KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff858c9b3b7540, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffff858c9b3b7498, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1796
Key : Analysis.Elapsed.mSec
Value: 21095
Key : Analysis.IO.Other.Mb
Value: 15
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 16
Key : Analysis.Init.CPU.mSec
Value: 468
Key : Analysis.Init.Elapsed.mSec
Value: 4613
Key : Analysis.Memory.CommitPeak.Mb
Value: 120
Key : Analysis.Version.DbgEng
Value: 10.0.27829.1001
Key : Analysis.Version.Description
Value: 10.2503.24.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2503.24.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : Dump.Attributes.AsUlong
Value: 0x21808
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : FailFast.Name
Value: CORRUPT_LIST_ENTRY
Key : FailFast.Type
Value: 3
Key : Failure.Bucket
Value: 0x139_3_CORRUPT_LIST_ENTRY_dxgkrnl!CTokenManager::ReleaseFlipManagerTokensToFrame
Key : Failure.Exception.Code
Value: 0xc0000409
Key : Failure.Exception.Record
Value: 0xffff858c9b3b7498
Key : Failure.Hash
Value: {1525b8cc-c868-2f52-835b-125462327a5b}
Key : Hypervisor.Enlightenments.ValueHex
Value: 0x7417df84
Key : Hypervisor.Flags.AnyHypervisorPresent
Value: 1
Key : Hypervisor.Flags.ApicEnlightened
Value: 0
Key : Hypervisor.Flags.ApicVirtualizationAvailable
Value: 1
Key : Hypervisor.Flags.AsyncMemoryHint
Value: 0
Key : Hypervisor.Flags.CoreSchedulerRequested
Value: 0
Key : Hypervisor.Flags.CpuManager
Value: 1
Key : Hypervisor.Flags.DeprecateAutoEoi
Value: 1
Key : Hypervisor.Flags.DynamicCpuDisabled
Value: 1
Key : Hypervisor.Flags.Epf
Value: 0
Key : Hypervisor.Flags.ExtendedProcessorMasks
Value: 1
Key : Hypervisor.Flags.HardwareMbecAvailable
Value: 1
Key : Hypervisor.Flags.MaxBankNumber
Value: 0
Key : Hypervisor.Flags.MemoryZeroingControl
Value: 0
Key : Hypervisor.Flags.NoExtendedRangeFlush
Value: 0
Key : Hypervisor.Flags.NoNonArchCoreSharing
Value: 1
Key : Hypervisor.Flags.Phase0InitDone
Value: 1
Key : Hypervisor.Flags.PowerSchedulerQos
Value: 0
Key : Hypervisor.Flags.RootScheduler
Value: 0
Key : Hypervisor.Flags.SynicAvailable
Value: 1
Key : Hypervisor.Flags.UseQpcBias
Value: 0
Key : Hypervisor.Flags.Value
Value: 55185662
Key : Hypervisor.Flags.ValueHex
Value: 0x34a10fe
Key : Hypervisor.Flags.VpAssistPage
Value: 1
Key : Hypervisor.Flags.VsmAvailable
Value: 1
Key : Hypervisor.RootFlags.AccessStats
Value: 1
Key : Hypervisor.RootFlags.CrashdumpEnlightened
Value: 1
Key : Hypervisor.RootFlags.CreateVirtualProcessor
Value: 1
Key : Hypervisor.RootFlags.DisableHyperthreading
Value: 0
Key : Hypervisor.RootFlags.HostTimelineSync
Value: 1
Key : Hypervisor.RootFlags.HypervisorDebuggingEnabled
Value: 0
Key : Hypervisor.RootFlags.IsHyperV
Value: 1
Key : Hypervisor.RootFlags.LivedumpEnlightened
Value: 1
Key : Hypervisor.RootFlags.MapDeviceInterrupt
Value: 1
Key : Hypervisor.RootFlags.MceEnlightened
Value: 1
Key : Hypervisor.RootFlags.Nested
Value: 0
Key : Hypervisor.RootFlags.StartLogicalProcessor
Value: 1
Key : Hypervisor.RootFlags.Value
Value: 1015
Key : Hypervisor.RootFlags.ValueHex
Value: 0x3f7
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff858c9b3b7540
BUGCHECK_P3: ffff858c9b3b7498
BUGCHECK_P4: 0
FILE_IN_CAB: 050625-9562-01.dmp
TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b
DUMP_FILE_ATTRIBUTES: 0x21808
Kernel Generated Triage Dump
FAULTING_THREAD: ffffbf0354af2080
TRAP_FRAME: ffff858c9b3b7540 -- (.trap 0xffff858c9b3b7540)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000003
rdx=ffffbf0354af2080 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800592932ac rsp=ffff858c9b3b76d0 rbp=ffff858c9b3b7710
r8=0000000000000000 r9=0000000000000001 r10=fffff800c761f920
r11=ffffbf0354af2080 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
dxgkrnl!CTokenManager::ReleaseFlipManagerTokensToFrame+0x270:
fffff800`592932ac cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff858c9b3b7498 -- (.exr 0xffff858c9b3b7498)
ExceptionAddress: fffff800592932ac (dxgkrnl!CTokenManager::ReleaseFlipManagerTokensToFrame+0x0000000000000270)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: dwm.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff858c`9b3b7218 fffff800`c7ab8fe9 : 00000000`00000139 00000000`00000003 ffff858c`9b3b7540 ffff858c`9b3b7498 : nt!KeBugCheckEx
ffff858c`9b3b7220 fffff800`c7ab95f2 : 00000000`00000001 00000000`00000000 ffffb803`49765226 fffff800`7e7a17f8 : nt!KiBugCheckDispatch+0x69
ffff858c`9b3b7360 fffff800`c7ab7228 : 00000000`00000000 fffff800`5e70bf2d ffff8980`455be650 ffff858c`9b3b7620 : nt!KiFastFailDispatch+0xb2
ffff858c`9b3b7540 fffff800`592932ac : ffff8980`26bba128 ffff8980`48da4720 ffff8980`253888b0 fffff800`592a7ce9 : nt!KiRaiseSecurityCheckFailure+0x368
ffff858c`9b3b76d0 fffff800`592d04ed : ffff8980`4b28fe30 ffff8980`26bba128 ffff8980`3b7c60c0 ffff8980`25388868 : dxgkrnl!CTokenManager::ReleaseFlipManagerTokensToFrame+0x270
ffff858c`9b3b7740 fffff800`5e86b017 : ffff8980`253887a0 ffff8980`3b7c60c0 ffff8980`26bba000 ffff858c`9b3b7920 : dxgkrnl!CTokenManager::ReleaseToFrame+0x3cd
ffff858c`9b3b77c0 fffff800`5e86aafa : ffff8980`3b7c60c0 ffff8980`4ba324f0 00000000`00000000 00000000`c000000d : win32kbase!DirectComposition::CConnection::BeginFrame+0x293
ffff858c`9b3b7820 fffff800`59172149 : 00000058`00000000 000001d1`dc14c3b8 00000038`f5effa00 00000000`00000004 : win32kbase!NtDCompositionBeginFrame+0x24a
ffff858c`9b3b79f0 fffff800`c7ab8655 : ffffbf03`54af2080 000001d1`dc14c3b8 ffffbf03`54af2080 00000000`00000000 : win32k!NtDCompositionBeginFrame+0x49
ffff858c`9b3b7a20 00007ffa`32833534 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000038`f5eff898 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`32833534
SYMBOL_NAME: dxgkrnl!CTokenManager::ReleaseFlipManagerTokensToFrame+270
MODULE_NAME: dxgkrnl
IMAGE_NAME: dxgkrnl.sys
IMAGE_VERSION: 10.0.26100.3912
STACK_COMMAND: .process /r /p 0xffffbf035415e080; .thread 0xffffbf0354af2080 ; kb
BUCKET_ID_FUNC_OFFSET: 270
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_dxgkrnl!CTokenManager::ReleaseFlipManagerTokensToFrame
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {1525b8cc-c868-2f52-835b-125462327a5b}
Followup: MachineOwner