KERNEL_SECURITY_CHECK_FAILURE

cattylord 0 Reputation points
2026-08-08T06:08:57.76+00:00

My PC has been crashing repeatedly with KERNEL_SECURITY_CHECK_FAILURE. It seems like it happens most often when something is trying to access files. It appears to happen randomly whenever my PC has been on for long enough, but I most consistently find it happening when I try to launch the game Destiny 2 after ~1 and a half hours of uptime. It also seems like putting my computer to sleep makes it more likely to happen for some reason.

I've looked through event viewer and I noticed that every time it happens, I get the same events in this order:
Error: BitLocker timed out attempting to enumerate bands during volume discovery on this hardware encrypting drive.

Information: Volume ?? (\Device\HarddiskVolume6) is healthy. No action is needed.

Error: BitLocker timed out attempting to enumerate bands during volume discovery on this hardware encrypting drive.

Error: BitLocker timed out attempting to enumerate bands during volume discovery on this hardware encrypting drive.

Error (Volmgr): Dump file generation succeded.

Followed by the critical error of the system crashing.

I've tried every recommended fix provided by others facing similar issues to no avail. From the errors, it seems like an issue with bitlocker but I have it disabled on all of my drives. Any help would be appreciated.

2: kd> !analyze -v
Loading Kernel Symbols
...............................................................
................................................................
................................................................
........................................
Loading User Symbols

Loading unloaded module list
........................................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure.  The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
Arg2: ffff940b5648eef0, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffff940b5648ee48, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1437

    Key  : Analysis.Elapsed.mSec
    Value: 1465

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 0

    Key  : Analysis.Init.CPU.mSec
    Value: 421

    Key  : Analysis.Init.Elapsed.mSec
    Value: 4462

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 84

    Key  : Analysis.Version.DbgEng
    Value: 10.0.29617.1000

    Key  : Analysis.Version.Description
    Value: 10.2604.29.1 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2604.29.1

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x139

    Key  : Bugcheck.Code.TargetModel
    Value: 0x139

    Key  : Dump.Attributes.AsUlong
    Value: 0x21808

    Key  : Dump.Attributes.DiagDataWrittenToHeader
    Value: 1

    Key  : Dump.Attributes.ErrorCode
    Value: 0x0

    Key  : Dump.Attributes.KernelGeneratedTriageDump
    Value: 1

    Key  : Dump.Attributes.LastLine
    Value: Dump completed successfully.

    Key  : Dump.Attributes.ProgressPercentage
    Value: 0

    Key  : FailFast.Name
    Value: CORRUPT_LIST_ENTRY

    Key  : FailFast.Type
    Value: 3

    Key  : Failure.Bucket
    Value: 0x139_3_CORRUPT_LIST_ENTRY_nt!KiFastFailDispatch

    Key  : Failure.Exception.Code
    Value: 0xc0000409

    Key  : Failure.Exception.Record
    Value: 0xffff940b5648ee48

    Key  : Failure.Hash
    Value: {3aede96a-54dd-40d6-d4cb-2a161a843851}

    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x7497cf94

    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 1

    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 1

    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 0

    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key  : Hypervisor.Flags.CpuManager
    Value: 1

    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 0

    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 1

    Key  : Hypervisor.Flags.Epf
    Value: 0

    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 1

    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 1

    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0

    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 1

    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 1

    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key  : Hypervisor.Flags.RootScheduler
    Value: 0

    Key  : Hypervisor.Flags.SynicAvailable
    Value: 1

    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0

    Key  : Hypervisor.Flags.Value
    Value: 38408431

    Key  : Hypervisor.Flags.ValueHex
    Value: 0x24a10ef

    Key  : Hypervisor.Flags.VpAssistPage
    Value: 1

    Key  : Hypervisor.Flags.VsmAvailable
    Value: 1

    Key  : Hypervisor.RootFlags.AccessStats
    Value: 1

    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 1

    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 1

    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 1

    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.Nested
    Value: 0

    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.Value
    Value: 1015

    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x3f7

    Key  : WER.System.BIOSRevision
    Value: 5.17.0.0


BUGCHECK_CODE:  139

BUGCHECK_P1: 3

BUGCHECK_P2: ffff940b5648eef0

BUGCHECK_P3: ffff940b5648ee48

BUGCHECK_P4: 0

FILE_IN_CAB:  080826-18515-01.dmp

TAG_NOT_DEFINED_202b:  *** Unknown TAG in analysis list 202b


DUMP_FILE_ATTRIBUTES: 0x21808
  Kernel Generated Triage Dump

FAULTING_THREAD:  ffffc08915ba4080

TRAP_FRAME:  ffff940b5648eef0 -- (.trap 0xffff940b5648eef0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffc08910f5d688 rbx=0000000000000000 rcx=0000000000000003
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8029e0c772a rsp=ffff940b5648f080 rbp=ffffd700bad00180
 r8=0000000000000000  r9=0000000000000000 r10=ffffc088fd7ff001
r11=ffffc088fc4c1208 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na po cy
nt!KiProcessThreadWaitList+0x17a:
fffff802`9e0c772a cd29            int     29h
Resetting default scope

EXCEPTION_RECORD:  ffff940b5648ee48 -- (.exr 0xffff940b5648ee48)
ExceptionAddress: fffff8029e0c772a (nt!KiProcessThreadWaitList+0x000000000000017a)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000003
Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY 

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)


CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  0000000000000003

EXCEPTION_STR:  0xc0000409

STACK_TEXT:  
ffff940b`5648ebc8 fffff802`9e4bfbe9     : 00000000`00000139 00000000`00000003 ffff940b`5648eef0 ffff940b`5648ee48 : nt!KeBugCheckEx
ffff940b`5648ebd0 fffff802`9e4c01f2     : 00400000`00000080 fffff802`00000000 03008a11`086070f6 00000000`00000048 : nt!KiBugCheckDispatch+0x69
ffff940b`5648ed10 fffff802`9e4bde28     : 00000000`00000000 fffff802`9ec15a80 00000000`00000000 fffff802`9e2e1097 : nt!KiFastFailDispatch+0xb2
ffff940b`5648eef0 fffff802`9e0c772a     : ffffc089`15ba4180 ffffd700`bb0d1180 00000000`00000002 ffffc089`15ba4080 : nt!KiRaiseSecurityCheckFailure+0x368
ffff940b`5648f080 fffff802`9e0c7376     : 00000000`00000000 ffffc089`00000001 ffffc089`00000000 00000000`00000000 : nt!KiProcessThreadWaitList+0x17a
ffff940b`5648f120 fffff802`9e0df5b0     : 00000002`bb351100 ffffc089`108ef040 ffffc089`108ef040 00000000`00000000 : nt!KiExitDispatcher+0x46
ffff940b`5648f180 fffff802`9e44f1c1     : 00000000`00000000 ffff940b`5648f270 ffff940b`5648f490 ffff940b`5648f490 : nt!KeInsertQueueApc+0x250
ffff940b`5648f230 fffff802`9e6eeb80     : 00000000`00000000 ffff940b`5648f490 ffffc089`108ef040 ffffc088`fc4c1040 : nt!EtwpTraceThreadRundownWithStack+0x11d
ffff940b`5648f340 fffff802`9e6eeaed     : ffffc089`4199d040 ffffc089`130b34c0 fffff802`9e6eeb40 ffffc088`fc4c1040 : nt!EtwpThreadEnumCallback+0x40
ffff940b`5648f370 fffff802`9e6ef4f0     : ffff940b`5648f5e0 ffff940b`5648f401 ffff940b`5648f490 ffffc088`fc4c1040 : nt!PsEnumProcessThreads+0x4d
ffff940b`5648f3a0 fffff802`9e65f987     : 00000000`00002000 ffffc088`fc7cc000 ffffc088`fc4c1040 fffff802`9e6ef220 : nt!EtwpProcessEnumCallback+0x2d0
ffff940b`5648f440 fffff802`9e80f5b5     : 00000000`00002000 ffff940b`5648f4e0 ffff940b`5648f5e0 fffff802`9e1b6962 : nt!PsEnumProcesses+0x73
ffff940b`5648f470 fffff802`9e80f0d1     : 00000000`00000000 ffff940b`5648f5e0 00000000`00000001 ffff940b`5648f5e0 : nt!EtwpProcessThreadImageRundown+0xb9
ffff940b`5648f500 fffff802`9e80efed     : 00000000`00000001 ffffc088`fc7cc000 ffffaa8c`00000020 00000000`00000020 : nt!EtwpKernelTraceRundown+0xbd
ffff940b`5648f570 fffff802`9e92a45f     : 00000000`00000000 00000000`00000020 ffffc088`fc7cc000 ffffaa8c`be0d0ce0 : nt!EtwpLogKernelTraceRundown+0x4d
ffff940b`5648f5b0 fffff802`9e80eb9b     : ffffaa8c`b4a51428 80000001`00000020 ffffc088`fc7cc001 ffffaa8c`9c6520a0 : nt!EtwpCheckGuidAccessAndDoRundown+0x11b6b3
ffff940b`5648f650 fffff802`9e83ec7d     : 00000000`00000001 ffff940b`5648f7c0 00000000`00000000 00000000`00000409 : nt!EtwpEnableDisableSpecialGuids+0x17f
ffff940b`5648f6c0 fffff802`9e8827e2     : 00000000`00000000 00000000`00001000 00000000`00000000 fffff802`9e04393b : nt!EtwpEnableGuid+0x26d
ffff940b`5648f910 fffff802`9e4bf258     : 00000000`00000011 00000000`0000000b 00000000`00000000 00000000`00000000 : nt!NtTraceControl+0x5a2
ffff940b`5648fa30 00007ffd`88203b14     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000000d`e83fd928 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`88203b14


SYMBOL_NAME:  nt!KiFastFailDispatch+b2

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.26100.8875

STACK_COMMAND: .process /r /p 0xffffc08916d82080; .thread /r /p 0xffffc08915ba4080 ; kb

BUCKET_ID_FUNC_OFFSET:  b2

FAILURE_BUCKET_ID:  0x139_3_CORRUPT_LIST_ENTRY_nt!KiFastFailDispatch

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {3aede96a-54dd-40d6-d4cb-2a161a843851}

Followup:     MachineOwner
---------

Windows for home | Windows 11 | Performance and system failures
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-08T06:09:21.9066667+00:00

    KERNEL_SECURITY_CHECK_FAILURE (bug check 0x139) means Windows detected corruption of a critical kernel data structure. One common 0x139 case is Parameter 1 = 3, which indicates a corrupted LIST_ENTRY, often caused by a driver mismanaging linked-list data, freeing a structure too early, double-removing an entry, or updating a list concurrently without proper synchronization.

    Given the pattern described:

    1. Focus on drivers and recent hardware/software changes
      • If any hardware was added recently, remove or reseat it.
      • If any device drivers or low-level system software were added or updated recently, remove or update them.
      • This stop code is commonly tied to driver corruption rather than BitLocker itself.
    2. Check Device Manager for a faulting device
      • Right-click Start > Device Manager.
      • Look for devices with an exclamation mark !.
      • Open the device properties and review the device/driver events.
      • Update the related driver.
    3. Check Event Viewer around the crash window
      • Open Event Viewer and review the System log.
      • Look for critical or error events in the same time window as the blue screen.
      • The BitLocker timeout entries may be adjacent symptoms; the stop code guidance points to checking for the device or driver that is failing in that same period.
    4. Check free disk space
      • Keep roughly 10% to 15% free space available on the system drive.
      • Low free space can interfere with swap-file and related system operations.
    5. Run System File Checker
      • Open an elevated Command Prompt and run:
             SFC /scannow
        
      • This checks for and repairs missing or corrupted Windows system files.
    6. Test without sleep/resume and with recent driver updates reverted
      • Since sleep appears to increase the likelihood, test from a fresh boot and avoid sleep temporarily.
      • If the issue started after a storage, chipset, GPU, or other device-driver update, roll back or reinstall that driver.
    7. If a dump file is available, analyze the bug check parameters
      • For 0x139, Parameter 1 identifies the corruption type.
      • If Parameter 1 is 3, that strongly points to LIST_ENTRY corruption and a driver issue.
      • Examining multiple dump files for the same pattern is recommended.
    8. If the issue began after a recent system change, use System Restore
      • Go to recovery options and restore to a point before the crashes began.
      • This can reverse a problematic driver or system change.
    9. Run hardware diagnostics from the PC manufacturer
      • This is especially useful if driver updates do not help.

    The BitLocker timeout messages alone do not establish BitLocker as the root cause. The documented guidance for 0x139 points first to kernel/driver corruption analysis, Device Manager, Event Viewer correlation, recent driver or hardware changes, and dump analysis.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.