Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

the windows 10 crashed after watch video with firefox a long time(>20min)

  • No replies
  • 1 has this problem
  • 116 views
more options

As i watch this video this video for a long time, the windows 10 crashed and raise a blue screen with error KERNEL_SECURITY_CHECK_FAILURE。

after the system restart, i analysis the dmp file and found something maybe help you debug the bug.

KERNEL_SECURITY_CHECK_FAILURE (139) A kernel component has corrupted a critical data structure. The corruption could potentially allow a malicious user to gain control of this machine. Arguments: Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove). Arg2: fffffd8e4b4c79f0, Address of the trap frame for the exception that caused the bugcheck Arg3: fffffd8e4b4c7948, Address of the exception record for the exception that caused the bugcheck Arg4: 0000000000000000, Reserved

Debugging Details:



KEY_VALUES_STRING: 1

   Key  : Analysis.CPU.Sec
   Value: 3
   Key  : Analysis.DebugAnalysisProvider.CPP
   Value: Create: 8007007e on xxxxxxx
   Key  : Analysis.DebugData
   Value: CreateObject
   Key  : Analysis.DebugModel
   Value: CreateObject
   Key  : Analysis.Elapsed.Sec
   Value: 82
   Key  : Analysis.Memory.CommitPeak.Mb
   Value: 89
   Key  : Analysis.System
   Value: CreateObject


BUGCHECK_CODE: 139

BUGCHECK_P1: 3

BUGCHECK_P2: fffffd8e4b4c79f0

BUGCHECK_P3: fffffd8e4b4c7948

BUGCHECK_P4: 0

TRAP_FRAME: fffffd8e4b4c79f0 -- (.trap 0xfffffd8e4b4c79f0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffdb01deb9f198 rbx=0000000000000000 rcx=0000000000000003 rdx=ffffdb02051e9158 rsi=0000000000000000 rdi=0000000000000000 rip=fffff806825de511 rsp=fffffd8e4b4c7b80 rbp=ffffb401e129e180

r8=0000000000000102  r9=0000000000000000 r10=fffff8067eb38800

r11=0000000000000007 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz ac pe cy nt!KiTryUnwaitThread+0x12b7c1: fffff806`825de511 cd29 int 29h Resetting default scope

EXCEPTION_RECORD: fffffd8e4b4c7948 -- (.exr 0xfffffd8e4b4c7948) ExceptionAddress: fffff806825de511 (nt!KiTryUnwaitThread+0x000000000012b7c1)

  ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
 ExceptionFlags: 00000001

NumberParameters: 1

  Parameter[0]: 0000000000000003

Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: firefox.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text>

EXCEPTION_CODE_STR: c0000409

EXCEPTION_PARAMETER1: 0000000000000003

DPC_STACK_BASE: FFFFFD8E4B4C7FB0

EXCEPTION_STR: 0xc0000409

STACK_TEXT: fffffd8e`4b4c76c8 fffff806`825d41e9 : 00000000`00000139 00000000`00000003 fffffd8e`4b4c79f0 fffffd8e`4b4c7948 : nt!KeBugCheckEx fffffd8e`4b4c76d0 fffff806`825d4610 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69 fffffd8e`4b4c7810 fffff806`825d29a3 : 00000000`1a74bf66 fffff806`87889437 00000000`00000000 fffff806`8235dd04 : nt!KiFastFailDispatch+0xd0 fffffd8e`4b4c79f0 fffff806`825de511 : ffff2dcd`203293aa ffffdb01`e0258080 00000000`00000206 fffff806`824b1084 : nt!KiRaiseSecurityCheckFailure+0x323 fffffd8e`4b4c7b80 fffff806`82451666 : ffffdb01`deb9f1c8 00000000`00000000 ffffdb01`deb9f290 ffffdb01`deb9f1c0 : nt!KiTryUnwaitThread+0x12b7c1 fffffd8e`4b4c7be0 fffff806`82451242 : ffffdb01`deb9f1c0 ffffdb01`e02581f0 cd3f400f`00000003 00000409`00000002 : nt!KiTimerWaitTest+0x1b6 fffffd8e`4b4c7c90 fffff806`82450039 : 00000000`0000001e 00000000`00989680 00000000`01025c1d 00000000`00000035 : nt!KiProcessExpiredTimerList+0xd2 fffffd8e`4b4c7d80 fffff806`825c93a5 : 00000000`00000000 ffffb401`e129e180 ffffdb01`cd0c6e00 00000000`00000000 : nt!KiRetireDpcList+0x4e9 fffffd8e`4b4c7fb0 fffff806`825c9190 : ffffdb01`cd0c6e00 fffff806`8235f37b 0000024f`5f5168d0 00007fff`ccf97fc0 : nt!KxRetireDpcList+0x5 fffffd8e`520d79c0 fffff806`825c8a45 : 00000000`00000000 fffff806`825c4411 00000000`00000460 fffffd8e`520d7a80 : nt!KiDispatchInterruptContinue fffffd8e`520d79f0 fffff806`825c4411 : 00000000`00000460 fffffd8e`520d7a80 ffffdb01`cd0c6e00 fffffd8e`520d7a80 : nt!KiDpcInterruptBypass+0x25 fffffd8e`520d7a00 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiInterruptDispatchNoLockNoEtw+0xb1


SYMBOL_NAME: nt!KiTimerWaitTest+1b6

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

IMAGE_VERSION: 10.0.18362.900

STACK_COMMAND: .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET: 1b6

FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiTimerWaitTest

OS_VERSION: 10.0.18362.1

BUILDLAB_STR: 19h1_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {efb56395-a173-53f8-073d-d3c8cfd50e2b}

As i watch this video [https://www.bilibili.com/video/BV14t4y1i7Ge this video] for a long time, the windows 10 crashed and raise a blue screen with error KERNEL_SECURITY_CHECK_FAILURE。 after the system restart, i analysis the dmp file and found something maybe help you debug the bug. KERNEL_SECURITY_CHECK_FAILURE (139) A kernel component has corrupted a critical data structure. The corruption could potentially allow a malicious user to gain control of this machine. Arguments: Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove). Arg2: fffffd8e4b4c79f0, Address of the trap frame for the exception that caused the bugcheck Arg3: fffffd8e4b4c7948, Address of the exception record for the exception that caused the bugcheck Arg4: 0000000000000000, Reserved Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : Analysis.CPU.Sec Value: 3 Key : Analysis.DebugAnalysisProvider.CPP Value: Create: 8007007e on xxxxxxx Key : Analysis.DebugData Value: CreateObject Key : Analysis.DebugModel Value: CreateObject Key : Analysis.Elapsed.Sec Value: 82 Key : Analysis.Memory.CommitPeak.Mb Value: 89 Key : Analysis.System Value: CreateObject BUGCHECK_CODE: 139 BUGCHECK_P1: 3 BUGCHECK_P2: fffffd8e4b4c79f0 BUGCHECK_P3: fffffd8e4b4c7948 BUGCHECK_P4: 0 TRAP_FRAME: fffffd8e4b4c79f0 -- (.trap 0xfffffd8e4b4c79f0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffdb01deb9f198 rbx=0000000000000000 rcx=0000000000000003 rdx=ffffdb02051e9158 rsi=0000000000000000 rdi=0000000000000000 rip=fffff806825de511 rsp=fffffd8e4b4c7b80 rbp=ffffb401e129e180 r8=0000000000000102 r9=0000000000000000 r10=fffff8067eb38800 r11=0000000000000007 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz ac pe cy nt!KiTryUnwaitThread+0x12b7c1: fffff806`825de511 cd29 int 29h Resetting default scope EXCEPTION_RECORD: fffffd8e4b4c7948 -- (.exr 0xfffffd8e4b4c7948) ExceptionAddress: fffff806825de511 (nt!KiTryUnwaitThread+0x000000000012b7c1) ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001 NumberParameters: 1 Parameter[0]: 0000000000000003 Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY BLACKBOXBSD: 1 (!blackboxbsd) BLACKBOXNTFS: 1 (!blackboxntfs) BLACKBOXPNP: 1 (!blackboxpnp) BLACKBOXWINLOGON: 1 CUSTOMER_CRASH_COUNT: 1 PROCESS_NAME: firefox.exe ERROR_CODE: (NTSTATUS) 0xc0000409 - <Unable to get error code text> EXCEPTION_CODE_STR: c0000409 EXCEPTION_PARAMETER1: 0000000000000003 DPC_STACK_BASE: FFFFFD8E4B4C7FB0 EXCEPTION_STR: 0xc0000409 STACK_TEXT: fffffd8e`4b4c76c8 fffff806`825d41e9 : 00000000`00000139 00000000`00000003 fffffd8e`4b4c79f0 fffffd8e`4b4c7948 : nt!KeBugCheckEx fffffd8e`4b4c76d0 fffff806`825d4610 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69 fffffd8e`4b4c7810 fffff806`825d29a3 : 00000000`1a74bf66 fffff806`87889437 00000000`00000000 fffff806`8235dd04 : nt!KiFastFailDispatch+0xd0 fffffd8e`4b4c79f0 fffff806`825de511 : ffff2dcd`203293aa ffffdb01`e0258080 00000000`00000206 fffff806`824b1084 : nt!KiRaiseSecurityCheckFailure+0x323 fffffd8e`4b4c7b80 fffff806`82451666 : ffffdb01`deb9f1c8 00000000`00000000 ffffdb01`deb9f290 ffffdb01`deb9f1c0 : nt!KiTryUnwaitThread+0x12b7c1 fffffd8e`4b4c7be0 fffff806`82451242 : ffffdb01`deb9f1c0 ffffdb01`e02581f0 cd3f400f`00000003 00000409`00000002 : nt!KiTimerWaitTest+0x1b6 fffffd8e`4b4c7c90 fffff806`82450039 : 00000000`0000001e 00000000`00989680 00000000`01025c1d 00000000`00000035 : nt!KiProcessExpiredTimerList+0xd2 fffffd8e`4b4c7d80 fffff806`825c93a5 : 00000000`00000000 ffffb401`e129e180 ffffdb01`cd0c6e00 00000000`00000000 : nt!KiRetireDpcList+0x4e9 fffffd8e`4b4c7fb0 fffff806`825c9190 : ffffdb01`cd0c6e00 fffff806`8235f37b 0000024f`5f5168d0 00007fff`ccf97fc0 : nt!KxRetireDpcList+0x5 fffffd8e`520d79c0 fffff806`825c8a45 : 00000000`00000000 fffff806`825c4411 00000000`00000460 fffffd8e`520d7a80 : nt!KiDispatchInterruptContinue fffffd8e`520d79f0 fffff806`825c4411 : 00000000`00000460 fffffd8e`520d7a80 ffffdb01`cd0c6e00 fffffd8e`520d7a80 : nt!KiDpcInterruptBypass+0x25 fffffd8e`520d7a00 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiInterruptDispatchNoLockNoEtw+0xb1 SYMBOL_NAME: nt!KiTimerWaitTest+1b6 MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe IMAGE_VERSION: 10.0.18362.900 STACK_COMMAND: .thread ; .cxr ; kb BUCKET_ID_FUNC_OFFSET: 1b6 FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_KTIMER_LIST_CORRUPTION_nt!KiTimerWaitTest OS_VERSION: 10.0.18362.1 BUILDLAB_STR: 19h1_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 FAILURE_ID_HASH: {efb56395-a173-53f8-073d-d3c8cfd50e2b}