Hi Steven,
Thank you for providing such a detailed investigation.
Based on the information you've shared, I am not aware of any publicly documented known issue, KB article, or Release Health notice for Windows 11 25H2 (build 26200.8655) describing an unbounded "Toke" paged-pool leak.
Your ETW traces indicate that the allocations originate during token creation (SepDuplicateToken / SeSubProcessToken) and persist after the child process exits. While this is certainly unexpected behavior, the stack alone cannot determine which component is holding the final reference. Security products (such as Microsoft Defender for Endpoint or third-party EDR solutions) may legitimately retain token references through process creation callbacks, so they cannot be completely ruled out based on allocation stacks alone.
To further isolate the issue, I would recommend:
- Reproducing the issue in a clean environment, if possible, without third-party security software.
- Collecting a kernel memory dump or additional ETW traces that include object reference information.
- Comparing the behavior on another Windows 11 build or Insider Preview build to determine whether the issue has already been addressed.
Regarding your questions:
- Known issue: I am not aware of a publicly documented issue for build 26200.8655 matching this behavior.
- Future fix: There is no published information indicating that this issue is scheduled to be addressed in a future cumulative update.
- Submitting traces: If you have a reproducible scenario and ETL files of this size, the recommended approach is to open a Microsoft Unified/Premier Support case. The support team can securely collect the ETL, memory dumps, and additional diagnostics, then engage the Windows engineering team if the investigation indicates a product issue.
Given the depth of your analysis and the reproducible test case, I believe opening a support case would be the most appropriate next step, as engineering has access to private symbols and internal diagnostics that are not available through the public forums.Hi Steven,
Thank you for providing such a detailed investigation.
Based on the information you've shared, I am not aware of any publicly documented known issue, KB article, or Release Health notice for Windows 11 25H2 (build 26200.8655) describing an unbounded "Toke" paged-pool leak.
Your ETW traces indicate that the allocations originate during token creation (SepDuplicateToken / SeSubProcessToken) and persist after the child process exits. While this is certainly unexpected behavior, the stack alone cannot determine which component is holding the final reference. Security products (such as Microsoft Defender for Endpoint or third-party EDR solutions) may legitimately retain token references through process creation callbacks, so they cannot be completely ruled out based on allocation stacks alone.
To further isolate the issue, I would recommend:
- Reproducing the issue in a clean environment, if possible, without third-party security software.
- Collecting a kernel memory dump or additional ETW traces that include object reference information.
- Comparing the behavior on another Windows 11 build or Insider Preview build to determine whether the issue has already been addressed.
Regarding your questions:
- Known issue: I am not aware of a publicly documented issue for build 26200.8655 matching this behavior.
- Future fix: There is no published information indicating that this issue is scheduled to be addressed in a future cumulative update.
- Submitting traces: If you have a reproducible scenario and ETL files of this size, the recommended approach is to open a Microsoft Unified/Premier Support case. The support team can securely collect the ETL, memory dumps, and additional diagnostics, then engage the Windows engineering team if the investigation indicates a product issue.
Given the depth of your analysis and the reproducible test case, I believe opening a support case would be the most appropriate next step, as engineering has access to private symbols and internal diagnostics that are not available through the public forums.