Microsoft (R) Windows Debugger Version 10.0.25136.1001 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:\temp\122823-7078-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available ************* Path validation summary ************** Response Time (ms) Location Deferred srv* Symbol search path is: srv* Executable search path is: Windows 10 Kernel Version 22621 MP (12 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Personal Edition build lab: 22621.1.amd64fre.ni_release.220506-1250 Machine Name: Kernel base = 0xfffff806`62600000 PsLoadedModuleList = 0xfffff806`632134a0 Debug session time: Thu Dec 28 11:41:48.004 2023 (UTC + 1:00) System Uptime: 0 days 0:04:34.666 Loading Kernel Symbols ............................................................... ................................................................ ......................................................... Loading User Symbols Loading unloaded module list ............... For analysis of this file, run !analyze -v nt!KeBugCheckEx: fffff806`62a16b00 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffe18f`9f053780=000000000000000a 2: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_NOT_LESS_OR_EQUAL (a) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If a kernel debugger is available get the stack backtrace. Arguments: Arg1: ffffa65b7669e8fc, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status) Arg4: fffff8066287b262, address which referenced memory Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 4561 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 19647 Key : Analysis.Init.CPU.mSec Value: 499 Key : Analysis.Init.Elapsed.mSec Value: 4205 Key : Analysis.Memory.CommitPeak.Mb Value: 87 Key : Bugcheck.Code.DumpHeader Value: 0xa Key : Bugcheck.Code.Register Value: 0xa Key : WER.OS.Branch Value: ni_release Key : WER.OS.Timestamp Value: 2022-05-06T12:50:00Z Key : WER.OS.Version Value: 10.0.22621.1 FILE_IN_CAB: 122823-7078-01.dmp BUGCHECK_CODE: a BUGCHECK_P1: ffffa65b7669e8fc BUGCHECK_P2: 2 BUGCHECK_P3: 1 BUGCHECK_P4: fffff8066287b262 WRITE_ADDRESS: fffff8066331d470: Unable to get MiVisibleState Unable to get NonPagedPoolStart Unable to get NonPagedPoolEnd Unable to get PagedPoolStart Unable to get PagedPoolEnd unable to get nt!MmSpecialPagesInUse ffffa65b7669e8fc BLACKBOXBSD: 1 (!blackboxbsd) BLACKBOXNTFS: 1 (!blackboxntfs) BLACKBOXPNP: 1 (!blackboxpnp) BLACKBOXWINLOGON: 1 CUSTOMER_CRASH_COUNT: 1 PROCESS_NAME: System TRAP_FRAME: ffffe18f9f0538c0 -- (.trap 0xffffe18f9f0538c0) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=00000000a3dd8aa8 rbx=0000000000000000 rcx=0000000000065168 rdx=00000000ad7b908e rsi=0000000000000000 rdi=0000000000000000 rip=fffff8066287b262 rsp=ffffe18f9f053a50 rbp=ffffe18f9f053b58 r8=0000000000100000 r9=ffffa65b7669e8fc r10=0000000000989680 r11=fffff78080003000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl zr na po nc nt!EtwpReserveTraceBuffer+0x1f2: fffff806`6287b262 498901 mov qword ptr [r9],rax ds:ffffa65b`7669e8fc=???????????????? Resetting default scope STACK_TEXT: ffffe18f`9f053778 fffff806`62a2c4e9 : 00000000`0000000a ffffa65b`7669e8fc 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx ffffe18f`9f053780 fffff806`62a27a34 : 00000000`00200001 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69 ffffe18f`9f0538c0 fffff806`6287b262 : ffffba8e`2869d718 00000000`00000000 ffffba8e`ffffffff ffffe18f`9f053ab0 : nt!KiPageFault+0x474 ffffe18f`9f053a50 fffff806`62ade3b1 : ffff77ff`41400000 ffffba8e`2a955080 00000000`00000000 ffffa65b`7669e8fc : nt!EtwpReserveTraceBuffer+0x1f2 ffffe18f`9f053b10 fffff806`62989062 : ffffba8e`00000000 ffffba8e`2a955080 ffffba8e`1f15b080 ffffba8e`00000002 : nt!EtwpLogContextSwapEvent+0x1552f1 ffffe18f`9f053bc0 fffff806`62a20875 : ffff8800`9ee5f180 000f807f`bcbbbdff ffffba8e`1f15b080 ffff8800`00000000 : nt!EtwTraceContextSwap+0xb2 ffffe18f`9f053c00 fffff806`62a1bb06 : 00000000`00000000 00000000`00000000 ffffba8e`1f15b080 ffffba8e`2a88c080 : nt!SwapContext+0x645 ffffe18f`9f053c40 00000000`00000000 : ffffe18f`9f054000 ffffe18f`9f04e000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x176 SYMBOL_NAME: nt!EtwpReserveTraceBuffer+1f2 MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe IMAGE_VERSION: 10.0.22621.2861 STACK_COMMAND: .cxr; .ecxr ; kb BUCKET_ID_FUNC_OFFSET: 1f2 FAILURE_BUCKET_ID: AV_nt!EtwpReserveTraceBuffer OS_VERSION: 10.0.22621.1 BUILDLAB_STR: ni_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 FAILURE_ID_HASH: {1d158166-bd6f-aa27-3597-29cbe717ff1c} Followup: MachineOwner ---------