ntkrnlmp.exe AV_nt!MiBuildMdlForMappedFileFault

- C 60 평판 포인트
2026-07-08T02:18:01.48+00:00

kd> !analyze -v

Loading Kernel Symbols

...............................................................

................................................................

.....................................................

Loading User Symbols

PEB is paged out (Peb.Ldr = 00000000`031fb018). Type ".hh dbgerr001" for details

Loading unloaded module list

............


  •                                                                         *
    
  •                    Bugcheck Analysis                                    *
    
  •                                                                         *
    

IRQL_NOT_LESS_OR_EQUAL (a)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high. This is usually

caused by drivers using improper addresses.

If a kernel debugger is available get the stack backtrace.

Arguments:

Arg1: 0000000000000018, memory referenced

Arg2: 0000000000000002, IRQL

Arg3: 0000000000000000, bitfield :

bit 0 : value 0 = read operation, 1 = write operation

bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)

Arg4: fffff8070f03db9f, address which referenced memory

Debugging Details:


KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec

Value: 1781

Key  : Analysis.Elapsed.mSec

Value: 4187

Key  : Analysis.IO.Other.Mb

Value: 0

Key  : Analysis.IO.Read.Mb

Value: 1

Key  : Analysis.IO.Write.Mb

Value: 0

Key  : Analysis.Init.CPU.mSec

Value: 640

Key  : Analysis.Init.Elapsed.mSec

Value: 11736

Key  : Analysis.Memory.CommitPeak.Mb

Value: 75

Key  : Analysis.Version.DbgEng

Value: 10.0.29617.1000

Key  : Analysis.Version.Description

Value: 10.2604.29.1 amd64fre

Key  : Analysis.Version.Ext

Value: 1.2604.29.1

Key  : Bugcheck.Code.LegacyAPI

Value: 0xa

Key  : Bugcheck.Code.TargetModel

Value: 0xa

Key  : Failure.Bucket

Value: AV_nt!MiBuildMdlForMappedFileFault

Key  : Failure.Exception.IP.Address

Value: 0xfffff8070f03db9f

Key  : Failure.Exception.IP.Module

Value: nt

Key  : Failure.Exception.IP.Offset

Value: 0x23db9f

Key  : Failure.Hash

Value: {c407c6c1-d4a7-f981-803d-0fe5946c178b}

Key  : Faulting.IP.Type

Value: Paged

Key  : WER.OS.Branch

Value: vb_release

Key  : WER.OS.Version

Value: 10.0.19041.1

Key  : WER.System.BIOSRevision

Value: 5.27.0.0

BUGCHECK_CODE: a

BUGCHECK_P1: 18

BUGCHECK_P2: 2

BUGCHECK_P3: 0

BUGCHECK_P4: fffff8070f03db9f

FILE_IN_CAB: 011526-4609-01.dmp

FAULTING_THREAD: ffffad8cfe0c8080

READ_ADDRESS: fffff8070fafb390: Unable to get MiVisibleState

0000000000000018

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: MicrosoftEdgeUpdate.exe

IP_IN_PAGED_CODE:

nt!MiBuildMdlForMappedFileFault+45f

fffff807`0f03db9f 498b4518 mov rax,qword ptr [r13+18h]

STACK_TEXT:

fffffe86f4c9f108 fffff8070f2124a9 : 000000000000000a 0000000000000018 0000000000000002 0000000000000000 : nt!KeBugCheckEx

fffffe86f4c9f110 fffff8070f20de78 : ffffc7000039e8e0 0000000000001000 0000000000000000 ffffc7000039e8d8 : nt!KiBugCheckDispatch+0x69

fffffe86f4c9f250 fffff8070f03db9f : 0000000000151b6e fffffe86f4c9f4e0 fffff8070fa50d40 0000000000000000 : nt!KiPageFault+0x478

fffffe86f4c9f3e0 fffff8070f11970b : fffff8070fa50d40 ffffad8d00dc4ba0 0000000000000000 ffff988f52deab48 : nt!MiBuildMdlForMappedFileFault+0x45f

fffffe86f4c9f530 fffff8070f016595 : fffffe86f4c9f7c0 ffff988f52deaf00 ffff818018134790 fffffe86f4c9f7a0 : nt!MiResolveMappedFileFault+0x44b

fffffe86f4c9f660 fffff8070f00f295 : fffffe86f4c9f7c0 0000000000000000 fffffe86f4c9f7a0 ffffad8cffcf8700 : nt!MiResolveProtoPteFault+0x1205

fffffe86f4c9f760 fffff8070f00d1d9 : 000000000323e2c8 0000000000000100 00000000c0000016 ffff988f52deaf00 : nt!MiDispatchFault+0x3d5

fffffe86f4c9f8a0 fffff8070f20dd6d : ffffad8cfe0c8000 00007ff9eeeb4720 fffffe86f4c9fac0 00000000031fd000 : nt!MmAccessFault+0x189

fffffe86f4c9fa40 000000007794583b : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : nt!KiPageFault+0x36d

000000000333f2bc 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : 0x7794583b

SYMBOL_NAME: nt!MiBuildMdlForMappedFileFault+45f

MODULE_NAME: nt

IMAGE_VERSION: 10.0.19041.6807

STACK_COMMAND: .process /r /p 0xffffad8cffcf8080; .thread /r /p 0xffffad8cfe0c8080 ; kb

IMAGE_NAME: ntkrnlmp.exe

BUCKET_ID_FUNC_OFFSET: 45f

FAILURE_BUCKET_ID: AV_nt!MiBuildMdlForMappedFileFault

OS_VERSION: 10.0.19041.1

BUILDLAB_STR: vb_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {c407c6c1-d4a7-f981-803d-0fe5946c178b}

Followup: MachineOwner


6: kd> .process /r /p 0xffffad8cffcf8080; .thread /r /p 0xffffad8cfe0c8080 ; kb

Implicit process is now ffffad8c`ffcf8080

Loading User Symbols

PEB is paged out (Peb.Ldr = 00000000`031fb018). Type ".hh dbgerr001" for details

Implicit thread is now ffffad8c`fe0c8080

Implicit process is now ffffad8c`ffcf8080

Loading User Symbols

PEB is paged out (Peb.Ldr = 00000000`031fb018). Type ".hh dbgerr001" for details

*** Stack trace for last set context - .thread/.cxr resets it

RetAddr : Args to Child : Call Site

00 fffff8070f2124a9 : 000000000000000a 0000000000000018 0000000000000002 00000000`00000000 : nt!KeBugCheckEx

01 fffff8070f20de78 : ffffc7000039e8e0 0000000000001000 0000000000000000 ffffc700`0039e8d8 : nt!KiBugCheckDispatch+0x69

02 fffff8070f03db9f : 0000000000151b6e fffffe86f4c9f4e0 fffff8070fa50d40 00000000`00000000 : nt!KiPageFault+0x478

03 fffff8070f11970b : fffff8070fa50d40 ffffad8d00dc4ba0 0000000000000000 ffff988f`52deab48 : nt!MiBuildMdlForMappedFileFault+0x45f

04 fffff8070f016595 : fffffe86f4c9f7c0 ffff988f52deaf00 ffff818018134790 fffffe86`f4c9f7a0 : nt!MiResolveMappedFileFault+0x44b

05 fffff8070f00f295 : fffffe86f4c9f7c0 0000000000000000 fffffe86f4c9f7a0 ffffad8c`ffcf8700 : nt!MiResolveProtoPteFault+0x1205

06 fffff8070f00d1d9 : 000000000323e2c8 0000000000000100 00000000c0000016 ffff988f`52deaf00 : nt!MiDispatchFault+0x3d5

07 fffff8070f20dd6d : ffffad8cfe0c8000 00007ff9eeeb4720 fffffe86f4c9fac0 00000000`031fd000 : nt!MmAccessFault+0x189

08 000000007794583b : 0000000000000000 0000000000000000 0000000000000000 00000000`00000000 : nt!KiPageFault+0x36d

09 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 00000000`00000000 : 0x7794583b

6: kd> .process /r /p 0xffffad8cffcf8080; .thread /r /p 0xffffad8cfe0c8080 ; kb

Implicit process is now ffffad8c`ffcf8080

Loading User Symbols

PEB is paged out (Peb.Ldr = 00000000`031fb018). Type ".hh dbgerr001" for details

Implicit thread is now ffffad8c`fe0c8080

Implicit process is now ffffad8c`ffcf8080

Loading User Symbols

PEB is paged out (Peb.Ldr = 00000000`031fb018). Type ".hh dbgerr001" for details

*** Stack trace for last set context - .thread/.cxr resets it

RetAddr : Args to Child : Call Site

00 fffff8070f2124a9 : 000000000000000a 0000000000000018 0000000000000002 00000000`00000000 : nt!KeBugCheckEx

01 fffff8070f20de78 : ffffc7000039e8e0 0000000000001000 0000000000000000 ffffc700`0039e8d8 : nt!KiBugCheckDispatch+0x69

02 fffff8070f03db9f : 0000000000151b6e fffffe86f4c9f4e0 fffff8070fa50d40 00000000`00000000 : nt!KiPageFault+0x478

03 fffff8070f11970b : fffff8070fa50d40 ffffad8d00dc4ba0 0000000000000000 ffff988f`52deab48 : nt!MiBuildMdlForMappedFileFault+0x45f

04 fffff8070f016595 : fffffe86f4c9f7c0 ffff988f52deaf00 ffff818018134790 fffffe86`f4c9f7a0 : nt!MiResolveMappedFileFault+0x44b

05 fffff8070f00f295 : fffffe86f4c9f7c0 0000000000000000 fffffe86f4c9f7a0 ffffad8c`ffcf8700 : nt!MiResolveProtoPteFault+0x1205

06 fffff8070f00d1d9 : 000000000323e2c8 0000000000000100 00000000c0000016 ffff988f`52deaf00 : nt!MiDispatchFault+0x3d5

07 fffff8070f20dd6d : ffffad8cfe0c8000 00007ff9eeeb4720 fffffe86f4c9fac0 00000000`031fd000 : nt!MmAccessFault+0x189

08 000000007794583b : 0000000000000000 0000000000000000 0000000000000000 00000000`00000000 : nt!KiPageFault+0x36d

09 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 00000000`00000000 : 0x7794583b

6: kd> lmvm nt

Browse full module list

start end module name

fffff8070ee00000 fffff8070fe46000 nt (pdb symbols) C:\ProgramData\Dbg\sym\ntkrnlmp.pdb\DFE5A00EF3F2E5952C223D63ED6EEAB01\ntkrnlmp.pdb

Loaded symbol image file: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\2FBE96761046000\ntkrnlmp.exe

Mapped memory image file: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\2FBE96761046000\ntkrnlmp.exe

Image path: ntkrnlmp.exe

Image name: ntkrnlmp.exe

Browse all global symbols  functions  data  Symbol Reload

Image was built with /Brepro flag.

Timestamp:        2FBE9676 (This is a reproducible build file hash, not a timestamp)

CheckSum:         00A5DA02

ImageSize:        01046000

Mapping Form:     Loaded

File version:     10.0.19041.6807

Product version:  10.0.19041.6807

File flags:       0 (Mask 3F)

File OS:          40004 NT Win32

File type:        1.0 App

File date:        00000000.00000000

Translations:     0409.04b0

InternalName: ntkrnlmp.exe

    OriginalFilename: ntkrnlmp.exe

    ProductVersion:   10.0.19041.6807

    FileVersion:      10.0.19041.6807 (WinBuild.160101.0800)

    FileDescription:  NT Kernel & System
비즈니스용 Windows | IoT용 Windows
댓글 0개 설명 없음

답변 1개

정렬 기준: 가장 유용함
  1. Xuan Nhu 1,370 평판 포인트 독립 자문가
    2026-07-08T06:16:45.8433333+00:00

    Hi, this dump does not prove that ntkrnlmp.exe is the root cause; it only shows the crash occurred while the Windows memory manager was handling a mapped-file page fault in nt!MiBuildMdlForMappedFileFault. Bugcheck 0xA IRQL_NOT_LESS_OR_EQUAL means code accessed an invalid or pageable address at too high an IRQL, and Microsoft documents that this is commonly caused by kernel-mode drivers using bad addresses or pageable code incorrectly. In your case, Arg1 is 0x18, Arg2 is 2 and Arg3 is 0, so this was a read from a near-null invalid address at DISPATCH_LEVEL; MicrosoftEdgeUpdate.exe is most likely the process that triggered the memory access path, not necessarily the faulty component. Because the stack contains only nt frames and this appears to be a small dump, the next step is to collect a kernel or complete memory dump, plus msinfo32, driverquery /v, and the loaded third-party driver list from WinDbg using lm t n. I would first update or temporarily remove third-party storage, antivirus/EDR, encryption, backup, filter, and filesystem-related drivers, because the failing path is mapped-file/MDL handling and the dump also captured BLACKBOXNTFS. If the crash is reproducible, use Driver Verifier only against non-Microsoft drivers on a test or maintenance window machine, because Microsoft documents Driver Verifier as a tool for detecting illegal driver actions that can intentionally force crashes to identify the faulty driver. Also confirm whether this system is Windows 10/IoT based on build 19041.6807, because the dump metadata does not match Windows 11, and make sure the device is fully patched with current BIOS, chipset, storage, and security-agent versions before treating this as an OS kernel bug.

    이 대답이 도움이 되었나요?

    댓글 0개 설명 없음

답변

질문 작성자는 답변을 '승인됨'으로 표시하고, 중재자는 답변을 '추천됨'으로 표시할 수 있습니다. 이를 통해 사용자는 해당 답변이 작성자의 문제를 해결했다는 것을 알 수 있습니다.