ERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff9b0c14d955e0, Address of the trap frame for the exception that caused the bugcheck
Arg3: ffff9b0c14d95538, Address of the exception record for the exception that caused the bugcheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 4
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-MOP7MJ5
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 47
Key : Analysis.Memory.CommitPeak.Mb
Value: 70
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff9b0c14d955e0
BUGCHECK_P3: ffff9b0c14d95538
BUGCHECK_P4: 0
TRAP_FRAME: ffff9b0c14d955e0 -- (.trap 0xffff9b0c14d955e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffda8f8dda61a0 rbx=0000000000000000 rcx=0000000000000003
rdx=ffffda8f8fbcf1a0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80711835eb7 rsp=ffff9b0c14d95770 rbp=0000000000001980
r8=0000000000000001 r9=00000000000000bc r10=0000000000000000
r11=fffff80711400000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
nt!KiCancelTimer+0x1cef67:
fffff807`11835eb7 cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff9b0c14d95538 -- (.exr 0xffff9b0c14d95538)
ExceptionAddress: fffff80711835eb7 (nt!KiCancelTimer+0x00000000001cef67)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: opera.exe
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff9b0c`14d952b8 fffff807`11807769 : 00000000`00000139 00000000`00000003 ffff9b0c`14d955e0 ffff9b0c`14d95538 : nt!KeBugCheckEx
ffff9b0c`14d952c0 fffff807`11807b90 : 00000000`00000002 ffff9f80`042a0180 00000000`00000002 fffff807`1164b0b6 : nt!KiBugCheckDispatch+0x69
ffff9b0c`14d95400 fffff807`11805f23 : 00000001`ffffffff fffffff6`00000007 ffff9b0c`14d957c0 00000000`00000000 : nt!KiFastFailDispatch+0xd0
ffff9b0c`14d955e0 fffff807`11835eb7 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323
ffff9b0c`14d95770 fffff807`11665a1c : ffff9f80`00000000 00000000`00000000 ffffda8f`90005de0 00000000`00000000 : nt!KiCancelTimer+0x1cef67
ffff9b0c`14d95820 fffff807`11664d7f : ffffda8f`00000002 00000000`00000005 ffff9b0c`14d959e0 fffff807`00000000 : nt!KiSwapThread+0x6cc
ffff9b0c`14d958d0 fffff807`11664623 : ffffda8f`000000bc fffff807`00000000 00000000`00000001 ffffda8f`8fbcf1c0 : nt!KiCommitThreadWait+0x14f
ffff9b0c`14d95970 fffff807`11a2c6a1 : ffffda8f`8fbb1b60 00000255`00000006 ffff9b0c`14d95a01 000000a6`5affe700 : nt!KeWaitForSingleObject+0x233
ffff9b0c`14d95a60 fffff807`11a2c74a : ffffda8f`8fbcf080 000000a6`5afff568 00000000`00000000 00000255`a6c49960 : nt!ObWaitForSingleObject+0x91
ffff9b0c`14d95ac0 fffff807`118071b8 : 00000000`00000001 ffffda8f`8fb3a480 ffff9b0c`14d95b18 ffffffff`fd46d370 : nt!NtWaitForSingleObject+0x6a
ffff9b0c`14d95b00 00007ffa`0eecc034 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
000000a6`5afff538 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`0eecc034
SYMBOL_NAME: nt!KiCancelTimer+1cef67
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.685
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 1cef67
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiCancelTimer
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {0a906956-eabe-15a9-fdee-848f8aa430ba}
Followup: MachineOwne