5692 Total CVEs
26 Years
GitHub
README.md
Rendering markdown...
POC / windbg_crash_logs.md MD
```
0: kd> g
Target is not responding.  Attempting to reconnect...
KDTARGET: Refreshing KD connection

*** Fatal System Error: 0x00000050
                       (0xFFFF87014D20F000,0x0000000000000002,0xFFFFF8070E44422B,0x0000000000000002)

Driver at fault: 
***      HTTP.sys - Address FFFFF8070E44422B base at FFFFF8070E2E0000, DateStamp a74c7183
.
Break instruction exception - code 80000003 (first chance)

A fatal system error has occurred.
Debugger entered on first try; Bugcheck callbacks have not been invoked.

A fatal system error has occurred.

For analysis of this file, run !analyze -v
nt!DbgBreakPointWithStatus:
fffff801`94b892d0 cc              int     3
0: kd> !analyze -v
Target is not responding.  Attempting to reconnect...
Connected to Windows 10 26100 x64 target at (Wed Jun 17 00:44:05.324 2026 (UTC - 7:00)), ptr64 TRUE
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.........
Loading User Symbols

Loading unloaded module list
.........
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff87014d20f000, memory referenced.
Arg2: 0000000000000002, X64: bit 0 set if the fault was due to a not-present PTE.
	bit 1 is set if the fault was due to a write, clear if a read.
	bit 3 is set if the processor decided the fault was due to a corrupted PTE.
	bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
	- ARM64: bit 1 is set if the fault was due to a write, clear if a read.
	bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: fffff8070e44422b, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------

Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...
Target is not responding.  Attempting to reconnect...

KEY_VALUES_STRING: 1

    Key  : AV.PTE
    Value: Invalid

    Key  : AV.Page.Virtual
    Value: 0xffff87014d200000

    Key  : AV.Type
    Value: Write

    Key  : Analysis.CPU.mSec
    Value: 17375

    Key  : Analysis.Elapsed.mSec
    Value: 72552

    Key  : Analysis.IO.Other.Mb
    Value: 5

    Key  : Analysis.IO.Read.Mb
    Value: 2

    Key  : Analysis.IO.Write.Mb
    Value: 0

    Key  : Analysis.Init.CPU.mSec
    Value: 13109

    Key  : Analysis.Init.Elapsed.mSec
    Value: 1530697

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 251

    Key  : Analysis.Version.DbgEng
    Value: 10.0.29547.1002

    Key  : Analysis.Version.Description
    Value: 10.2602.27.2 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2602.27.2

    Key  : Bugcheck.Code.KiBugCheckData
    Value: 0x50

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x50

    Key  : Bugcheck.Code.TargetModel
    Value: 0x50

    Key  : Failure.Bucket
    Value: AV_VRF_HTTP!memcpy

    Key  : Failure.Exception.IP.Address
    Value: 0xfffff8070e44422b

    Key  : Failure.Exception.IP.Module
    Value: HTTP

    Key  : Failure.Exception.IP.Offset
    Value: 0x16422b

    Key  : Failure.Hash
    Value: {92f0216a-fb7d-44d7-de19-f8985ede1fdb}

    Key  : Faulting.IP.Type
    Value: Paged

    Key  : Hypervisor.Enlightenments.Value
    Value: 12576

    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x3120

    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 1

    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 0

    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 0

    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key  : Hypervisor.Flags.CpuManager
    Value: 0

    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 1

    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 0

    Key  : Hypervisor.Flags.Epf
    Value: 0

    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 0

    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 0

    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 1

    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 0

    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 1

    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key  : Hypervisor.Flags.RootScheduler
    Value: 0

    Key  : Hypervisor.Flags.SynicAvailable
    Value: 1

    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0

    Key  : Hypervisor.Flags.Value
    Value: 536632

    Key  : Hypervisor.Flags.ValueHex
    Value: 0x83038

    Key  : Hypervisor.Flags.VpAssistPage
    Value: 1

    Key  : Hypervisor.Flags.VsmAvailable
    Value: 0

    Key  : Hypervisor.RootFlags.AccessStats
    Value: 0

    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 0

    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 0

    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 0

    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 0

    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.Nested
    Value: 0

    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 0

    Key  : Hypervisor.RootFlags.Value
    Value: 0

    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x0

    Key  : SecureKernel.HalpHvciEnabled
    Value: 0

    Key  : WER.OS.Branch
    Value: ge_release

    Key  : WER.OS.Version
    Value: 10.0.26100.1


BUGCHECK_CODE:  50

BUGCHECK_P1: ffff87014d20f000

BUGCHECK_P2: 2

BUGCHECK_P3: fffff8070e44422b

BUGCHECK_P4: 2

FAULTING_THREAD:  ffff870fbd7b5080

EXCEPTION_PARAMETER1:  0000000000000001

EXCEPTION_PARAMETER2:  ffff87014d20f000

WRITE_ADDRESS: Target is not responding.  Attempting to reconnect...
 ffff87014d20f000 Special pool

MM_INTERNAL_CODE:  2

PROCESS_NAME:  System

IP_IN_PAGED_CODE: 
HTTP!memcpy+1eb
fffff807`0e44422b 0f2b59e0        movntps xmmword ptr [rcx-20h],xmm3

STACK_TEXT:  
ffffe703`fdee6738 fffff801`94c3fa92     : ffffe703`fdee67b8 00000000`00000001 00000000`00000080 fffff801`94d52901 : nt!DbgBreakPointWithStatus
ffffe703`fdee6740 fffff801`94c3efbe     : 00000000`00000003 ffffe703`fdee68a0 fffff801`94d52b90 ffffe703`fdee6e60 : nt!KiBugCheckDebugBreak+0x12
ffffe703`fdee67a0 fffff801`94b88557     : 00000000`00000000 fffff801`9499caf2 ffff8701`4d20f000 fffff801`95236341 : nt!KeBugCheck2+0xb2e
ffffe703`fdee6f30 fffff801`9499e960     : 00000000`00000050 ffff8701`4d20f000 00000000`00000002 ffffe703`fdee71d0 : nt!KeBugCheckEx+0x107
ffffe703`fdee6f70 fffff801`948d3e96     : 00000000`00000000 ffff8000`00000000 ffff8701`4d20f000 0000007f`fffffff8 : nt!MiSystemFault+0x850
ffffe703`fdee7060 fffff801`94d47fcb     : 00000000`00000000 00000000`00000028 00000000`c0000016 ffffe703`fdee7240 : nt!MmAccessFault+0x646
ffffe703`fdee71d0 fffff807`0e44422b     : fffff807`0e30a148 ffff870f`bf516b60 ffffe703`fdee7419 ffff870f`bf564240 : nt!KiPageFault+0x38b
ffffe703`fdee7368 fffff807`0e30a148     : ffff870f`bf516b60 ffffe703`fdee7419 ffff870f`bf564240 00000000`c0000016 : HTTP!memcpy+0x1eb
ffffe703`fdee7370 fffff807`0e309575     : fffff807`0e3093e0 ffff870f`f1d60d50 00000000`00000001 ffff870f`bf516b60 : HTTP!UlpParseNextRequest+0x528
ffffe703`fdee7480 fffff807`0e457145     : fffff807`0e3093e0 fffff807`0e3093e0 00000000`00000001 00000000`00000000 : HTTP!UlpHandleRequest+0x195
ffffe703`fdee7520 fffff801`94b0eaba     : ffff870f`ba182f90 fffff807`0e486f20 ffff870f`bd7b5080 fffff801`257ad180 : HTTP!UlpThreadPoolWorker+0x126545
ffffe703`fdee75b0 fffff801`94d39fa4     : fffff801`257ad180 ffff870f`bd7b5080 fffff801`94b0ea60 006f0069`00740061 : nt!PspSystemThreadStartup+0x5a
ffffe703`fdee7600 00000000`00000000     : ffffe703`fdee8000 ffffe703`fdee1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x34


SYMBOL_NAME:  HTTP!memcpy+1eb

MODULE_NAME: HTTP

IMAGE_NAME:  HTTP.sys

STACK_COMMAND: .process /r /p 0xffff870fb36e4040; .thread /r /p 0xffff870fbd7b5080 ; kb

BUCKET_ID_FUNC_OFFSET:  1eb

FAILURE_BUCKET_ID:  AV_VRF_HTTP!memcpy

OS_VERSION:  10.0.26100.1

BUILDLAB_STR:  ge_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {92f0216a-fb7d-44d7-de19-f8985ede1fdb}

Followup:     MachineOwner
---------

0: kd> k
 # Child-SP          RetAddr               Call Site
00 ffffe703`fdee6738 fffff801`94c3fa92     nt!DbgBreakPointWithStatus
01 ffffe703`fdee6740 fffff801`94c3efbe     nt!KiBugCheckDebugBreak+0x12
02 ffffe703`fdee67a0 fffff801`94b88557     nt!KeBugCheck2+0xb2e
03 ffffe703`fdee6f30 fffff801`9499e960     nt!KeBugCheckEx+0x107
04 ffffe703`fdee6f70 fffff801`948d3e96     nt!MiSystemFault+0x850
05 ffffe703`fdee7060 fffff801`94d47fcb     nt!MmAccessFault+0x646
06 ffffe703`fdee71d0 fffff807`0e44422b     nt!KiPageFault+0x38b
07 ffffe703`fdee7368 fffff807`0e30a148     HTTP!memcpy+0x1eb
08 ffffe703`fdee7370 fffff807`0e309575     HTTP!UlpParseNextRequest+0x528
09 ffffe703`fdee7480 fffff807`0e457145     HTTP!UlpHandleRequest+0x195
0a ffffe703`fdee7520 fffff801`94b0eaba     HTTP!UlpThreadPoolWorker+0x126545
0b ffffe703`fdee75b0 fffff801`94d39fa4     nt!PspSystemThreadStartup+0x5a
0c ffffe703`fdee7600 00000000`00000000     nt!KiStartSystemThread+0x34
0: kd> g
```