*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {20, fd36d0c0, fd36d260, 4a340018}
Probably caused by : win32k.sys ( win32k!_WinSqmFree+10 )
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 00000020, a pool block header size is corrupt.
Arg2: fd36d0c0, The pool entry we were looking for within the page.
Arg3: fd36d260, The next pool entry.
Arg4: 4a340018, (reserved)
Debugging Details:
------------------
BUGCHECK_STR: 0x19_20
POOL_ADDRESS: GetPointerFromAddress: unable to read from 82d6e828
Unable to read MiSystemVaType memory at 82d4ed80
fd36d0c0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: firefox.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 9750e9c8 to 82d27c4e
STACK_TEXT:
ad92fc14 9750e9c8 fd36d0c8 00000000 ad92fc30 nt!ExFreePoolWithTag+0x1b2
ad92fc24 974f2f4d fd36d0c8 ad92fc40 974f2f84 win32k!_WinSqmFree+0x10
ad92fc30 974f2f84 87287570 fd36d0c8 ad92fc5c win32k!ExFreeToPagedLookasideList+0x1e
ad92fc40 974fab51 fd36d0c8 00000008 04000000 win32k!FreeObject+0x23
ad92fc5c 974faa9c 41051377 ad92fd10 974dffde win32k!XEPALOBJ::vUnrefPalette+0x8e
ad92fcec 974fa73e fd36d0c8 00000000 00000000 win32k!SURFACE::bDeleteSurface+0x34d
ad92fd00 974e4d06 00000000 00000000 ff9b8948 win32k!SURFREF::bDeleteSurface+0x14
ad92fd14 974e005d 41051377 0012f58c 41051377 win32k!bDeleteSurface+0x20
ad92fd28 82c448ba 41051377 0012f5a0 76e470b4 win32k!NtGdiDeleteObjectApp+0x7f
ad92fd28 76e470b4 41051377 0012f5a0 76e470b4 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0012f5a0 00000000 00000000 00000000 00000000 0x76e470b4
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!_WinSqmFree+10
9750e9c8 5d pop ebp
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: win32k!_WinSqmFree+10
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4df2d2ee
FAILURE_BUCKET_ID: 0x19_20_win32k!_WinSqmFree+10
BUCKET_ID: 0x19_20_win32k!_WinSqmFree+10
Followup: MachineOwner