Random BSOD KMODE_EXCEPTION_NOT_HANDLED (1e) in pacer.sys when completing OID_GEN_RECEIVE_SCALE_PARAMETERS during boot up

Johannes Fellinger 20 Reputation points
2026-06-09T08:54:54.1+00:00

During system boot up (near 14 seconds system up time) we sometimes (1 out of many reboots) get a BSOD in pacer.sys when completing a OID_GEN_RECEIVE_SCALE_PARAMETERS.

By analyzing the OID request forwarding through the NDIS stack it seems like the InformationBuffer has a valid pointer until it reaches pacer.sys. When looking at the original request the InformationBuffer is invalid (0) while BytesRead is set, which leads to the crash in NDIS trying to access the InformationBuffer.

Could this be an issue due to one of the filter drivers in the stack?

Here is the target info:

Windows 10 Kernel Version 19041 MP (24 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Kernel base = 0xfffff801`7a400000 PsLoadedModuleList = 0xfffff801`7b02a820
Debug session time: Sun Jun  7 09:02:13.735 2026 (UTC + 2:00)
System Uptime: 0 days 0:00:14.336

Here is the "!analyze -v" output of a complete crash dump:

5: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common BugCheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8017f867cfa, The address that the exception occurred at
Arg3: ffff970485cef508, Parameter 0 of the exception
Arg4: ffff970485ceed40, Parameter 1 of the exception

Debugging Details:
------------------

*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ExceptionRecord                               ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ContextRecord                                 ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ExceptionRecord                               ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ContextRecord                                 ***
***                                                                   ***
*************************************************************************
SYMSRV:  BYINDEX: 0x40
         https://msdl.microsoft.com/download/symbols
         ntkrnlmp.exe
         3FEC999C1046000
SYMSRV:  BYINDEX: 0x40
         https://msdl.microsoft.com/download/symbols
         ntkrnlmp.exe
         3FEC999C1046000
SYMSRV:  UNC: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\3FEC999C1046000\msfz0\ntkrnlmp.exe - path not found
SYMSRV:  UNC: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\3FEC999C1046000\msfz0\ntkrnlmp.exe - path not found
SYMSRV:  PATH: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\3FEC999C1046000\ntkrnlmp.exe
SYMSRV:  PATH: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\3FEC999C1046000\ntkrnlmp.exe
SYMSRV:  RESULT: 0x00000000
SYMSRV:  RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\3FEC999C1046000\ntkrnlmp.exe - OK
DBGHELP: C:\ProgramData\Dbg\sym\ntkrnlmp.exe\3FEC999C1046000\ntkrnlmp.exe - OK

KEY_VALUES_STRING: 1

    Key  : AV.Page.Physical
    Value: 0x4c00000

    Key  : AV.Page.Virtual
    Value: 0xffff970485ce0000

    Key  : AV.Type
    Value: Unknown

    Key  : Analysis.CPU.mSec
    Value: 1984

    Key  : Analysis.Elapsed.mSec
    Value: 2058

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 2

    Key  : Analysis.Init.CPU.mSec
    Value: 2453

    Key  : Analysis.Init.Elapsed.mSec
    Value: 941738

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 109

    Key  : Analysis.Version.DbgEng
    Value: 10.0.29547.1002

    Key  : Analysis.Version.Description
    Value: 10.2602.27.2 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2602.27.2

    Key  : Bugcheck.Code.KiBugCheckData
    Value: 0x1e

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1e

    Key  : Bugcheck.Code.TargetModel
    Value: 0x1e

    Key  : Failure.Bucket
    Value: AV_pacer!PcFilterRequestComplete

    Key  : Failure.Exception.IP.Address
    Value: 0xfffff8017f867cfa

    Key  : Failure.Exception.IP.Module
    Value: ndis

    Key  : Failure.Exception.IP.Offset
    Value: 0x37cfa

    Key  : Failure.Hash
    Value: {44edb0fe-3234-dfa2-606d-357dc7309ae7}

    Key  : Faulting.IP.Type
    Value: Paged

    Key  : Hypervisor.Enlightenments.Value
    Value: 0

    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x0

    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 0

    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 0

    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 0

    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key  : Hypervisor.Flags.CpuManager
    Value: 0

    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 0

    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 0

    Key  : Hypervisor.Flags.Epf
    Value: 0

    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 0

    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 1

    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0

    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 0

    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 0

    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key  : Hypervisor.Flags.RootScheduler
    Value: 0

    Key  : Hypervisor.Flags.SynicAvailable
    Value: 0

    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0

    Key  : Hypervisor.Flags.Value
    Value: 131072

    Key  : Hypervisor.Flags.ValueHex
    Value: 0x20000

    Key  : Hypervisor.Flags.VpAssistPage
    Value: 0

    Key  : Hypervisor.Flags.VsmAvailable
    Value: 0

    Key  : Hypervisor.RootFlags.AccessStats
    Value: 0

    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 0

    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 0

    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 0

    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 0

    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 0

    Key  : Hypervisor.RootFlags.Nested
    Value: 0

    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 0

    Key  : Hypervisor.RootFlags.Value
    Value: 0

    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x0

    Key  : SecureKernel.HalpHvciEnabled
    Value: 0

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1

    Key  : WER.System.BIOSRevision
    Value: 5.22.0.0


BUGCHECK_CODE:  1e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8017f867cfa

BUGCHECK_P3: ffff970485cef508

BUGCHECK_P4: ffff970485ceed40

FILE_IN_CAB:  MEMORY.DMP

FAULTING_THREAD:  ffffab0c368ee040

EXCEPTION_PARAMETER1:  ffff970485cef508

EXCEPTION_PARAMETER2:  ffff970485ceed40

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)


PROCESS_NAME:  System

TRAP_FRAME:  ffff800000000000 -- (.trap 0xffff800000000000)
Unable to read trap frame at ffff8000`00000000
Resetting default scope

IP_IN_PAGED_CODE: 
ndis!ndisPostSetOpenRSSParametersHelper+22
fffff801`7f867cfa 410fb7480c      movzx   ecx,word ptr [r8+0Ch]

STACK_TEXT:  
ffff9704`85cee4c8 fffff801`7a915d3f     : 00000000`0000001e ffffffff`c0000005 fffff801`7f867cfa ffff9704`85cef508 : nt!KeBugCheckEx
ffff9704`85cee4d0 fffff801`7a81a246     : ffff9704`85ceed40 fffff801`7a714b85 ffff9704`85cef740 fffff801`7f867cfa : nt!KiFatalFilter+0x1f
ffff9704`85cee510 fffff801`7a7d094f     : fffff801`00000002 fffff801`7a4cf714 ffff9704`85cea000 ffff9704`85cf1000 : nt!KeExpandKernelStackAndCalloutInternal$filt$0+0x16
ffff9704`85cee550 fffff801`7a808e8f     : fffff801`7a4cf714 ffff9704`85ceeb30 fffff801`7a7d08b0 00000000`00000000 : nt!_C_specific_handler+0x9f
ffff9704`85cee5c0 fffff801`7a6e4117     : ffff9704`85ceeb30 00000000`00000000 ffff9704`85cef970 fffff801`7a6914a8 : nt!RtlpExecuteHandlerForException+0xf
ffff9704`85cee5f0 fffff801`7a709c56     : ffff9704`85cef508 ffff9704`85cef240 ffff9704`85cef508 ffffb307`070591a0 : nt!RtlDispatchException+0x297
ffff9704`85ceed10 fffff801`7a812cec     : 00000000`00001000 ffff9704`85cef5b0 ffff8000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffff9704`85cef3d0 fffff801`7a80e552     : ffff8700`0c7fa000 55555555`55555555 ffff8700`0c7eb100 ffff8700`0c7f6640 : nt!KiExceptionDispatch+0x12c
ffff9704`85cef5b0 fffff801`7f867cfa     : 00000000`0978008b ffff9704`85cef7b8 00000000`00000008 ffff9704`85cef7c0 : nt!KiPageFault+0x452
ffff9704`85cef740 fffff801`7f867c7a     : ffff9704`85d00350 ffff9704`85d00350 00000000`00000000 ffffab0c`38cdbb30 : ndis!ndisPostSetOpenRSSParametersHelper+0x22
ffff9704`85cef790 fffff801`7f867bbe     : ffff9704`85cef930 00000000`00000000 ffffab0c`38cdbb30 ffff9704`85d00350 : ndis!ndisPostSetOpenRSSParameters+0xae
ffff9704`85cef800 fffff801`7f83b2db     : ffff9704`85cef930 ffff9704`85d00350 ffff9704`85d00350 00000000`00000000 : ndis!ndisOidPostRSSParameters+0xfe
ffff9704`85cef860 fffff801`7f83e743     : 00000000`00000000 ffffab0c`368ee000 00000000`00000000 ffffab0c`38cdbb30 : ndis!ndisOidRequestComplete+0x12b
ffff9704`85cef910 fffff801`7a6914a8     : ffffab0c`368ee040 ffff9704`85d00398 ffffab0c`386878a0 00000000`00000000 : ndis!ndisFOidRequestCompleteInternal+0x83
ffff9704`85cef970 fffff801`7a69141d     : fffff801`7f83e6c0 ffffab0c`386878a0 fffff801`7f914048 ffff9704`85cefa68 : nt!KeExpandKernelStackAndCalloutInternal+0x78
ffff9704`85cef9e0 fffff801`7f83f1b6     : fffff801`7f914048 00000000`00000000 ffffab0c`386878a0 ffffab0c`3cd4a8a0 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffff9704`85cefa20 fffff801`87701185     : ffffab0c`3cd4a800 ffff9704`85cefb10 ffffab0c`385d2db0 ffffab0c`3cd4a8a0 : ndis!NdisFOidRequestComplete+0x1e6
ffff9704`85cefaa0 fffff801`7f83b4dc     : ffff9704`85cefba0 ffff9704`85cefba0 00000000`00000000 00000000`00010204 : pacer!PcFilterRequestComplete+0x75
ffff9704`85cefad0 fffff801`7f83e743     : 00000000`00000000 ffffab0c`368ee000 00000000`00000000 00000000`00000000 : ndis!ndisOidRequestComplete+0x32c
ffff9704`85cefb80 fffff801`7a6914a8     : ffffab0c`368ee040 ffffab0c`3cd4a5b8 ffffab0c`38bc58a0 00000000`00000000 : ndis!ndisFOidRequestCompleteInternal+0x83
ffff9704`85cefbe0 fffff801`7a69141d     : fffff801`7f83e6c0 ffffab0c`38bc58a0 fffff801`7f914048 ffff9704`85cefcd0 : nt!KeExpandKernelStackAndCalloutInternal+0x78
ffff9704`85cefc50 fffff801`7f83f1b6     : fffff801`7f914048 ffffab0c`3cd4a5b8 00000000`00000008 01000000`00100000 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffff9704`85cefc90 fffff801`876a2cee     : ffff9704`85cefe10 ffff9704`85cefe10 00000000`00000000 ffff9704`85cefe10 : ndis!NdisFOidRequestComplete+0x1e6
ffff9704`85cefd10 fffff801`7f83b4dc     : ffff9704`85cefe10 00000000`00000000 00000000`00010204 ffffab0c`3cd49580 : BPpcap+0x2cee
ffff9704`85cefd40 fffff801`7f83e743     : 00000000`00000000 ffffab0c`368ee000 00000000`00000000 00000000`00000000 : ndis!ndisOidRequestComplete+0x32c
ffff9704`85cefdf0 fffff801`7a6914a8     : ffffab0c`368ee040 ffffab0c`3cd495c8 ffffab0c`38bc28a0 00000000`00000000 : ndis!ndisFOidRequestCompleteInternal+0x83
ffff9704`85cefe50 fffff801`7a69141d     : fffff801`7f83e6c0 ffffab0c`38bc28a0 fffff801`7f914048 ffff9704`85ceff48 : nt!KeExpandKernelStackAndCalloutInternal+0x78
ffff9704`85cefec0 fffff801`7f83f1b6     : fffff801`7f914048 00000000`00000000 ffffab0c`38bc28a0 ffffab0c`3cd4caa0 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffff9704`85ceff00 fffff801`876c8f69     : ffffab0c`3cd4c300 ffffab0c`3cd4c330 00000000`00000000 ffffab0c`3cd4c330 : ndis!NdisFOidRequestComplete+0x1e6
ffff9704`85ceff80 fffff801`876c2dcd     : ffffab0c`3cd4c330 00000000`00000000 00000000`00010204 00000000`00000000 : brawcap!CompleteForwarded+0xa9
ffff9704`85ceffb0 fffff801`7f83b4dc     : ffff9704`85cf00b0 ffff9704`85cf00b0 ffffab0c`3cd4c330 00000000`00000000 : brawcap!BrcOidRequestCompleteEntryPoint+0x2d
ffff9704`85ceffe0 fffff801`7f83e743     : 00000000`00000000 ffffab0c`368ee000 00000000`00000000 00000000`00000000 : ndis!ndisOidRequestComplete+0x32c
ffff9704`85cf0090 fffff801`7a6914a8     : ffffab0c`368ee040 ffffab0c`3cd4c378 ffffab0c`38f91c30 00000000`00000000 : ndis!ndisFOidRequestCompleteInternal+0x83
ffff9704`85cf00f0 fffff801`7a69141d     : fffff801`7f83e6c0 ffffab0c`38f91c30 fffff801`7f914048 ffff9704`85cf01e0 : nt!KeExpandKernelStackAndCalloutInternal+0x78
ffff9704`85cf0160 fffff801`7f83f1b6     : fffff801`7f914048 ffffab0c`3cd4c378 00000000`00000008 01000000`00100000 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffff9704`85cf01a0 fffff801`7fe0199f     : ffffab0c`3cd4c330 ffff9704`85cf03a0 ffffab0c`374398e0 ffffab0c`3cd4c330 : ndis!NdisFOidRequestComplete+0x1e6
ffff9704`85cf0220 fffff801`7f83b4dc     : ffff9704`85cf03a0 00000000`00000000 00000000`00010204 fffff801`7f92a6a4 : wfplwfs!LwfLowerOidRequestComplete+0xdf
ffff9704`85cf0270 fffff801`7f83bcfb     : ffffb307`07059100 00000000`00000000 00000000`00000000 00000000`00000000 : ndis!ndisOidRequestComplete+0x32c
ffff9704`85cf0320 fffff801`7f870efb     : ffffb307`07059100 ffff9704`00010204 00000000`00000000 00000000`00000000 : ndis!ndisMDoOidRequest+0x3fb
ffff9704`85cf0410 fffff801`7f83c36a     : ffffab0c`3cd4ccc0 00000000`00010204 ffffab0c`38f91c30 ffffab0c`38f91c30 : ndis!ndisQueueOidRequest+0x24fc7
ffff9704`85cf0480 fffff801`7fe01ab3     : ffffab0c`3cd4c330 ffff9704`85cf0659 00000000`00000000 00000000`00000000 : ndis!NdisFOidRequest+0x10a
ffff9704`85cf0580 fffff801`7f83c17d     : ffffab0c`3cd4ccc0 00000000`00000000 00000000`00000000 ffff9704`85cf0659 : wfplwfs!LwfLowerOidRequest+0x93
ffff9704`85cf05b0 fffff801`7a6914a8     : 00000000`00000000 ffffb307`07059200 00000000`00000000 ffffab0c`368ee040 : ndis!ndisFDoOidRequestInternal+0x31d
ffff9704`85cf06c0 fffff801`7a69141d     : fffff801`7f83be60 ffffab0c`38f91c30 00000000`00000000 ffffab0c`3cd4c330 : nt!KeExpandKernelStackAndCalloutInternal+0x78
ffff9704`85cf0730 fffff801`7f84c15d     : ffffb307`070591a0 ffffab0c`38f91c00 ffffab0c`38bc28a0 ffff9704`85cf0850 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffff9704`85cf0770 fffff801`7f83c36a     : ffffab0c`3cd4c330 00000000`00010204 ffffab0c`38bc28a0 ffffab0c`38bc28a0 : ndis!ndisQueueOidRequest+0x229
ffff9704`85cf07e0 fffff801`876c9060     : ffffab0c`3cd4caa0 00000000`00000000 ffffab0c`38f0c130 00000000`00000000 : ndis!NdisFOidRequest+0x10a
ffff9704`85cf08e0 fffff801`7f83c17d     : ffffab0c`3cd4c330 00000000`00000000 ffff9704`85cf09b9 ffffab0c`3cd4caa0 : brawcap!Forward+0xd0
ffff9704`85cf0910 fffff801`7a6914a8     : ffffab0c`3cd4caa0 fffff801`7f914048 00000000`00000000 ffffab0c`368ee040 : ndis!ndisFDoOidRequestInternal+0x31d
ffff9704`85cf0a20 fffff801`7a69141d     : fffff801`7f83be60 ffffab0c`38bc28a0 ffffab0c`38bc28a0 ffff9704`85cf0b00 : nt!KeExpandKernelStackAndCalloutInternal+0x78
ffff9704`85cf0a90 fffff801`7f838455     : ffffab0c`38bc28a0 ffffab0c`3cc7b4e0 ffffb706`93602cb0 fffff801`7f8fb388 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffff9704`85cf0ad0 fffff801`7a622525     : ffffab0c`368ee040 ffffab0c`368ee040 fffff801`7f8383c0 ffffb706`93602cb0 : ndis!ndisDoOidRequests+0x95
ffff9704`85cf0b30 fffff801`7a7299a5     : ffffab0c`368ee040 00000000`00000080 ffffab0c`33e8b200 000fe467`bcbbbdff : nt!ExpWorkerThread+0x105
ffff9704`85cf0bd0 fffff801`7a807358     : ffff8700`0c740180 ffffab0c`368ee040 fffff801`7a729950 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffff9704`85cf0c20 00000000`00000000     : ffff9704`85cf1000 ffff9704`85cea000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28


SYMBOL_NAME:  pacer!PcFilterRequestComplete+75

MODULE_NAME: pacer

IMAGE_NAME:  pacer.sys

STACK_COMMAND: .process /r /p 0xffffab0c33e8b200; .thread /r /p 0xffffab0c368ee040 ; kb

BUCKET_ID_FUNC_OFFSET:  75

FAILURE_BUCKET_ID:  AV_pacer!PcFilterRequestComplete

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {44edb0fe-3234-dfa2-606d-357dc7309ae7}

Followup:     Machine
Windows development | Windows Driver Kit (WDK)

Answer accepted by question author
Taki Ly (WICLOUD CORPORATION) 5,625 Reputation points Microsoft External Staff Moderator
2026-06-10T03:29:22.3566667+00:00

Hello @Johannes Fellinger ,

Thank you for providing the initial crash dump details and the additional request payloads.

Looking at the provided stack trace and the extra data, it appears that the issue might be occurring during the completion path of the OID request.

Based on your follow-up, I noticed that the cloned requests processed by brawcap and BPpcap do contain a valid InformationBuffer pointer (0xffffab0c3e0de3d4). However, when the original request propagates back up to pacer.sys, the InformationBuffer unexpectedly becomes 0x0, while the BytesRead field remains set to 0x264.

The trace shows pacer!PcFilterRequestComplete and ndis!ndisPostSetOpenRSSParametersHelper processing the return path, with third-party drivers positioned below pacer.sys in the stack:

  1. brawcap!BrcOidRequestCompleteEntryPoint -> brawcap!CompleteForwarded
  2. BPpcap+0x2cee
  3. ndis!NdisFOidRequestComplete
  4. pacer!PcFilterRequestComplete

A common scenario in NDIS filter driver development that can lead to this behavior involves how cloned OID requests are handled upon completion. When a filter driver clones an OID request and passes it down the stack, it must ensure that when the request is completed, the resulting data (such as the InformationBuffer and BytesRead) is correctly mapped back to the original OID request before calling NdisFOidRequestComplete.

If an intermediate filter driver preserves the BytesRead value but fails to properly map or provide the InformationBuffer back to the original request, it could result in the upper layers (like NDIS or pacer.sys) attempting to access a null or invalid pointer. This mismatch directly aligns with the KMODE_EXCEPTION_NOT_HANDLED (1e) bugcheck you observed.

To help isolate the issue, I suggest the following steps:

  • If you are an administrator/user: I recommend temporarily disabling or uninstalling the applications associated with the brawcap.sys and BPpcap.sys filter drivers (often related to packet capture software like npcap/winpcap). This could help verify if these drivers are contributing to the instability during boot.
  • If you are developing the third-party filter drivers: I suggest reviewing the logic inside the OID completion handlers (e.g., CompleteForwarded). Specifically, verify that for OID_GEN_RECEIVE_SCALE_PARAMETERS, the original NDIS_OID_REQUEST structure is correctly updated and that the buffer pointers are valid before passing the request up the stack.

For further reference on handling OID requests within filter drivers, you might find these resources useful:

I hope this information assists you in debugging the issue. If you found my response helpful or informative, I would greatly appreciate it if you could follow this guide for your confirmation.

Thank you.

Was this answer helpful?

2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.