Hi Peter Camps,
Your poolmon.exe capture shows that the MSPi pool taghas nearly 12 million unfreed allocations consuming roughly 49 GB of Non-Paged Pool (Nonp) RAM after one week. You reproduced this exact Non-Paged Pool growth in a nested virtual Hyper-V cluster with no third-party drivers, the HPE Gen10 SPP firmware and Intel E810-XXVDA4 drivers are ruled out as root causes. While KB5101372 (the Servicing Stack Update bundled with the July 2026 Cumulative Update KB5099536, build 10.0.26100.33158) and the September 8, 2026 Cumulative Update KB5122871 (build 10.0.26100.33438) updated refs.sys, neither resolved this leak, and the September 14, 2026 Out-of-Band update (KB5129235, build 10.0.26100.33451) only addresses Remote Desktop and USB audio issues. This seems an unresolved Microsoft bug in refs.sys, there is no permanent fix yet, and you will need to wait for an official Microsoft Cumulative Update that patches the MSPi leak.
While waiting for an official Microsoft fix, you can configure Microsoft's documented ReFS metadata trimming parameters under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem on every cluster node by creating the REG_DWORD values RefsEnableLargeWorkingSetTrim set to 1, RefsEnableInlineTrim set to 1, and RefsNumberOfChunksToTrim set to 16 or 32, followed by a rolling node reboot. These parameters force refs.sys to unmap inactive metadata streams inline and at every checkpoint rather than relying on lazy garbage collection; however, because they primarily trim the ReFS metadata working set rather than freeing leaked MSPi Non-Paged Pool pages, they may only modestly reduce memory pressure. To preserve Non-Paged Pool headroom and prevent Srv Event ID 2019 pool exhaustion hangs, check (Get-Cluster).BlockCacheSize in PowerShell to ensure the CSV Block Cache (which also allocates from Non-Paged Pool RAM) is kept conservative, continue scheduling rolling node reboots via Suspend-ClusterNode -Drain, and log a support case with Microsoft Support with your poolmon.exe output and a non-disruptive kernel live dump (Get-StorageDiagnosticInfo or livekd) to escalate the refs.sys defect.
Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.
VPHAN