My PC has been crashing repeatedly with KERNEL_SECURITY_CHECK_FAILURE. It seems like it happens most often when something is trying to access files. It appears to happen randomly whenever my PC has been on for long enough, but I most consistently find it happening when I try to launch the game Destiny 2 after ~1 and a half hours of uptime. It also seems like putting my computer to sleep makes it more likely to happen for some reason.
I've looked through event viewer and I noticed that every time it happens, I get the same events in this order:
Error: BitLocker timed out attempting to enumerate bands during volume discovery on this hardware encrypting drive.
Information: Volume ?? (\Device\HarddiskVolume6) is healthy. No action is needed.
Error: BitLocker timed out attempting to enumerate bands during volume discovery on this hardware encrypting drive.
Error: BitLocker timed out attempting to enumerate bands during volume discovery on this hardware encrypting drive.
Error (Volmgr): Dump file generation succeded.
Followed by the critical error of the system crashing.
I've tried every recommended fix provided by others facing similar issues to no avail. From the errors, it seems like an issue with bitlocker but I have it disabled on all of my drives. Any help would be appreciated.
2: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................................
................................................................
........................................
Loading User Symbols
Loading unloaded module list
........................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff940b5648eef0, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffff940b5648ee48, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1437
Key : Analysis.Elapsed.mSec
Value: 1465
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 421
Key : Analysis.Init.Elapsed.mSec
Value: 4462
Key : Analysis.Memory.CommitPeak.Mb
Value: 84
Key : Analysis.Version.DbgEng
Value: 10.0.29617.1000
Key : Analysis.Version.Description
Value: 10.2604.29.1 amd64fre
Key : Analysis.Version.Ext
Value: 1.2604.29.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : Dump.Attributes.AsUlong
Value: 0x21808
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : FailFast.Name
Value: CORRUPT_LIST_ENTRY
Key : FailFast.Type
Value: 3
Key : Failure.Bucket
Value: 0x139_3_CORRUPT_LIST_ENTRY_nt!KiFastFailDispatch
Key : Failure.Exception.Code
Value: 0xc0000409
Key : Failure.Exception.Record
Value: 0xffff940b5648ee48
Key : Failure.Hash
Value: {3aede96a-54dd-40d6-d4cb-2a161a843851}
Key : Hypervisor.Enlightenments.ValueHex
Value: 0x7497cf94
Key : Hypervisor.Flags.AnyHypervisorPresent
Value: 1
Key : Hypervisor.Flags.ApicEnlightened
Value: 1
Key : Hypervisor.Flags.ApicVirtualizationAvailable
Value: 0
Key : Hypervisor.Flags.AsyncMemoryHint
Value: 0
Key : Hypervisor.Flags.CoreSchedulerRequested
Value: 0
Key : Hypervisor.Flags.CpuManager
Value: 1
Key : Hypervisor.Flags.DeprecateAutoEoi
Value: 0
Key : Hypervisor.Flags.DynamicCpuDisabled
Value: 1
Key : Hypervisor.Flags.Epf
Value: 0
Key : Hypervisor.Flags.ExtendedProcessorMasks
Value: 1
Key : Hypervisor.Flags.HardwareMbecAvailable
Value: 1
Key : Hypervisor.Flags.MaxBankNumber
Value: 0
Key : Hypervisor.Flags.MemoryZeroingControl
Value: 0
Key : Hypervisor.Flags.NoExtendedRangeFlush
Value: 0
Key : Hypervisor.Flags.NoNonArchCoreSharing
Value: 1
Key : Hypervisor.Flags.Phase0InitDone
Value: 1
Key : Hypervisor.Flags.PowerSchedulerQos
Value: 0
Key : Hypervisor.Flags.RootScheduler
Value: 0
Key : Hypervisor.Flags.SynicAvailable
Value: 1
Key : Hypervisor.Flags.UseQpcBias
Value: 0
Key : Hypervisor.Flags.Value
Value: 38408431
Key : Hypervisor.Flags.ValueHex
Value: 0x24a10ef
Key : Hypervisor.Flags.VpAssistPage
Value: 1
Key : Hypervisor.Flags.VsmAvailable
Value: 1
Key : Hypervisor.RootFlags.AccessStats
Value: 1
Key : Hypervisor.RootFlags.CrashdumpEnlightened
Value: 1
Key : Hypervisor.RootFlags.CreateVirtualProcessor
Value: 1
Key : Hypervisor.RootFlags.DisableHyperthreading
Value: 0
Key : Hypervisor.RootFlags.HostTimelineSync
Value: 1
Key : Hypervisor.RootFlags.HypervisorDebuggingEnabled
Value: 0
Key : Hypervisor.RootFlags.IsHyperV
Value: 1
Key : Hypervisor.RootFlags.LivedumpEnlightened
Value: 1
Key : Hypervisor.RootFlags.MapDeviceInterrupt
Value: 1
Key : Hypervisor.RootFlags.MceEnlightened
Value: 1
Key : Hypervisor.RootFlags.Nested
Value: 0
Key : Hypervisor.RootFlags.StartLogicalProcessor
Value: 1
Key : Hypervisor.RootFlags.Value
Value: 1015
Key : Hypervisor.RootFlags.ValueHex
Value: 0x3f7
Key : WER.System.BIOSRevision
Value: 5.17.0.0
BUGCHECK_CODE: 139
BUGCHECK_P1: 3
BUGCHECK_P2: ffff940b5648eef0
BUGCHECK_P3: ffff940b5648ee48
BUGCHECK_P4: 0
FILE_IN_CAB: 080826-18515-01.dmp
TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b
DUMP_FILE_ATTRIBUTES: 0x21808
Kernel Generated Triage Dump
FAULTING_THREAD: ffffc08915ba4080
TRAP_FRAME: ffff940b5648eef0 -- (.trap 0xffff940b5648eef0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffc08910f5d688 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8029e0c772a rsp=ffff940b5648f080 rbp=ffffd700bad00180
r8=0000000000000000 r9=0000000000000000 r10=ffffc088fd7ff001
r11=ffffc088fc4c1208 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po cy
nt!KiProcessThreadWaitList+0x17a:
fffff802`9e0c772a cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: ffff940b5648ee48 -- (.exr 0xffff940b5648ee48)
ExceptionAddress: fffff8029e0c772a (nt!KiProcessThreadWaitList+0x000000000000017a)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000003
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffff940b`5648ebc8 fffff802`9e4bfbe9 : 00000000`00000139 00000000`00000003 ffff940b`5648eef0 ffff940b`5648ee48 : nt!KeBugCheckEx
ffff940b`5648ebd0 fffff802`9e4c01f2 : 00400000`00000080 fffff802`00000000 03008a11`086070f6 00000000`00000048 : nt!KiBugCheckDispatch+0x69
ffff940b`5648ed10 fffff802`9e4bde28 : 00000000`00000000 fffff802`9ec15a80 00000000`00000000 fffff802`9e2e1097 : nt!KiFastFailDispatch+0xb2
ffff940b`5648eef0 fffff802`9e0c772a : ffffc089`15ba4180 ffffd700`bb0d1180 00000000`00000002 ffffc089`15ba4080 : nt!KiRaiseSecurityCheckFailure+0x368
ffff940b`5648f080 fffff802`9e0c7376 : 00000000`00000000 ffffc089`00000001 ffffc089`00000000 00000000`00000000 : nt!KiProcessThreadWaitList+0x17a
ffff940b`5648f120 fffff802`9e0df5b0 : 00000002`bb351100 ffffc089`108ef040 ffffc089`108ef040 00000000`00000000 : nt!KiExitDispatcher+0x46
ffff940b`5648f180 fffff802`9e44f1c1 : 00000000`00000000 ffff940b`5648f270 ffff940b`5648f490 ffff940b`5648f490 : nt!KeInsertQueueApc+0x250
ffff940b`5648f230 fffff802`9e6eeb80 : 00000000`00000000 ffff940b`5648f490 ffffc089`108ef040 ffffc088`fc4c1040 : nt!EtwpTraceThreadRundownWithStack+0x11d
ffff940b`5648f340 fffff802`9e6eeaed : ffffc089`4199d040 ffffc089`130b34c0 fffff802`9e6eeb40 ffffc088`fc4c1040 : nt!EtwpThreadEnumCallback+0x40
ffff940b`5648f370 fffff802`9e6ef4f0 : ffff940b`5648f5e0 ffff940b`5648f401 ffff940b`5648f490 ffffc088`fc4c1040 : nt!PsEnumProcessThreads+0x4d
ffff940b`5648f3a0 fffff802`9e65f987 : 00000000`00002000 ffffc088`fc7cc000 ffffc088`fc4c1040 fffff802`9e6ef220 : nt!EtwpProcessEnumCallback+0x2d0
ffff940b`5648f440 fffff802`9e80f5b5 : 00000000`00002000 ffff940b`5648f4e0 ffff940b`5648f5e0 fffff802`9e1b6962 : nt!PsEnumProcesses+0x73
ffff940b`5648f470 fffff802`9e80f0d1 : 00000000`00000000 ffff940b`5648f5e0 00000000`00000001 ffff940b`5648f5e0 : nt!EtwpProcessThreadImageRundown+0xb9
ffff940b`5648f500 fffff802`9e80efed : 00000000`00000001 ffffc088`fc7cc000 ffffaa8c`00000020 00000000`00000020 : nt!EtwpKernelTraceRundown+0xbd
ffff940b`5648f570 fffff802`9e92a45f : 00000000`00000000 00000000`00000020 ffffc088`fc7cc000 ffffaa8c`be0d0ce0 : nt!EtwpLogKernelTraceRundown+0x4d
ffff940b`5648f5b0 fffff802`9e80eb9b : ffffaa8c`b4a51428 80000001`00000020 ffffc088`fc7cc001 ffffaa8c`9c6520a0 : nt!EtwpCheckGuidAccessAndDoRundown+0x11b6b3
ffff940b`5648f650 fffff802`9e83ec7d : 00000000`00000001 ffff940b`5648f7c0 00000000`00000000 00000000`00000409 : nt!EtwpEnableDisableSpecialGuids+0x17f
ffff940b`5648f6c0 fffff802`9e8827e2 : 00000000`00000000 00000000`00001000 00000000`00000000 fffff802`9e04393b : nt!EtwpEnableGuid+0x26d
ffff940b`5648f910 fffff802`9e4bf258 : 00000000`00000011 00000000`0000000b 00000000`00000000 00000000`00000000 : nt!NtTraceControl+0x5a2
ffff940b`5648fa30 00007ffd`88203b14 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000000d`e83fd928 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`88203b14
SYMBOL_NAME: nt!KiFastFailDispatch+b2
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.26100.8875
STACK_COMMAND: .process /r /p 0xffffc08916d82080; .thread /r /p 0xffffc08915ba4080 ; kb
BUCKET_ID_FUNC_OFFSET: b2
FAILURE_BUCKET_ID: 0x139_3_CORRUPT_LIST_ENTRY_nt!KiFastFailDispatch
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {3aede96a-54dd-40d6-d4cb-2a161a843851}
Followup: MachineOwner
---------