How to fix Kernel heap mode corruption (0x13A)

Gwen Ryza Petilla 20 Reputation points
2026-08-19T11:27:27.4733333+00:00

I've been experiencing Kernel Heap Mode Corruption BSOD, I've tried a few things they told me to do:

  1. Ran /sfc scannow and DISM.exe /Online /Cleanup-Image /Restorehealth
  2. Reinstalled GPU drivers
  3. Ran a memory test

My device is lenovo idepad slim 3

......................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

KERNEL_MODE_HEAP_CORRUPTION (13a)
The kernel mode heap manager has detected corruption in a heap.
Arguments:
Arg1: 0000000000000017, The heap detected that a block was corrupted in a delay free list. This is likely a use-after-free error or a buffer overflow of an adjacent block.
Arg2: ffffa08500100340, Address of the heap that reported the corruption
Arg3: ffffa08532c83fe0, Address at which the corruption was detected
Arg4: 0000000000000000

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 2218

    Key  : Analysis.Elapsed.mSec
    Value: 14440

    Key  : Analysis.IO.Other.Mb
    Value: 4

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 27

    Key  : Analysis.Init.CPU.mSec
    Value: 968

    Key  : Analysis.Init.Elapsed.mSec
    Value: 37558

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 89

    Key  : Analysis.Version.DbgEng
    Value: 10.0.29617.1000

    Key  : Analysis.Version.Description
    Value: 10.2604.29.1 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2604.29.1

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x13a

    Key  : Bugcheck.Code.TargetModel
    Value: 0x13a

    Key  : Dump.Attributes.AsUlong
    Value: 0x21808

    Key  : Dump.Attributes.DiagDataWrittenToHeader
    Value: 1

    Key  : Dump.Attributes.ErrorCode
    Value: 0x0

    Key  : Dump.Attributes.KernelGeneratedTriageDump
    Value: 1

    Key  : Dump.Attributes.LastLine
    Value: Dump completed successfully.

    Key  : Dump.Attributes.ProgressPercentage
    Value: 0

    Key  : Failure.Bucket
    Value: 0x13a_17_nt!RtlpHeapHandleError

    Key  : Failure.Hash
    Value: {b1500314-0083-90bd-d812-716f3060523d}

    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x7417df84

    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 1

    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 0

    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 1

    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key  : Hypervisor.Flags.CpuManager
    Value: 1

    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 1

    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 1

    Key  : Hypervisor.Flags.Epf
    Value: 0

    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 1

    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 1

    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0

    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 1

    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 1

    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key  : Hypervisor.Flags.RootScheduler
    Value: 0

    Key  : Hypervisor.Flags.SynicAvailable
    Value: 1

    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0

    Key  : Hypervisor.Flags.Value
    Value: 55185662

    Key  : Hypervisor.Flags.ValueHex
    Value: 0x34a10fe

    Key  : Hypervisor.Flags.VpAssistPage
    Value: 1

    Key  : Hypervisor.Flags.VsmAvailable
    Value: 1

    Key  : Hypervisor.RootFlags.AccessStats
    Value: 1

    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 1

    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 1

    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 1

    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.Nested
    Value: 0

    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.Value
    Value: 1015

    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x3f7


BUGCHECK_CODE:  13a

BUGCHECK_P1: 17

BUGCHECK_P2: ffffa08500100340

BUGCHECK_P3: ffffa08532c83fe0

BUGCHECK_P4: 0

FILE_IN_CAB:  081926-17546-01.dmp

TAG_NOT_DEFINED_202b:  *** Unknown TAG in analysis list 202b


DUMP_FILE_ATTRIBUTES: 0x21808
  Kernel Generated Triage Dump

FAULTING_THREAD:  ffffa0852ebfa040

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon) (!blackboxwinlogonnotify)


CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

STACK_TEXT:  
ffff9286`be8f6d88 fffff803`b5bf07fc     : 00000000`0000013a 00000000`00000017 ffffa085`00100340 ffffa085`32c83fe0 : nt!KeBugCheckEx
ffff9286`be8f6d90 fffff803`b5bf085c     : 00000000`00000017 000ffffa`08532c82 ffffa085`00100340 00000000`00001000 : nt!RtlpHeapHandleError+0x40
ffff9286`be8f6dd0 fffff803`b5951209     : 00000000`000000f8 00000000`00000000 00000000`02000103 00000000`00000000 : nt!RtlpHpHeapHandleError+0x58
ffff9286`be8f6e00 fffff803`b59d88eb     : ffffa084`400a7248 00000000`00000010 00000000`00000001 00000000`00000009 : nt!RtlpLogHeapFailure+0x45
ffff9286`be8f6e30 fffff803`b59d841c     : ffffa085`00104bd8 00000000`00000020 00000000`001300ff 000ffffa`08532c82 : nt!RtlpHpLfhSubsegmentDelayFreeListProcess+0x2bb
ffff9286`be8f6eb0 fffff803`b5a35fbf     : ffffa085`00104bc0 00000000`001300ff ffffa085`00101c40 00000000`00000001 : nt!RtlpHpLfhOwnerRunMaintenance+0x14c
ffff9286`be8f6f10 fffff803`b5a360fa     : ffffa085`00101c40 ffff9286`be8f70b0 ffff9286`be8f70a0 ffffa085`00101c40 : nt!RtlpHpLfhOwnerCompact+0xbf
ffff9286`be8f7090 fffff803`b5a35dff     : ffffa085`00100000 ffffa085`00101c40 ffff2b00`298309d6 00000000`00000000 : nt!RtlpHpLfhOwnerCompact+0x1fa
ffff9286`be8f7210 fffff803`b5952355     : ffffa085`00100000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlpHpLfhContextCompact+0xbf
ffff9286`be8f7250 fffff803`b59522f3     : 00000000`00000001 ffffa085`004d5d00 00000000`00000001 ffffa085`2ebfa180 : nt!RtlpHpHeapCompact+0x21
ffff9286`be8f7280 fffff803`b5a82655     : 00000000`00000001 00000000`00000001 00000000`00000000 ffff9286`be8f7300 : nt!ExpHpCompactHeapCallback+0x23
ffff9286`be8f72b0 fffff803`b5a825b5     : 00000000`00000001 ffff9286`be8f7440 ffffa085`005975e0 ffffa085`005975e0 : nt!ExpHpEnumerateHeaps+0x71
ffff9286`be8f7310 fffff803`b5924f5b     : ffffa085`2ebfa040 ffff9286`be8f7400 ffff9286`be8f7400 ffffa085`005975e0 : nt!ExpHpCompactionRoutine+0x15
ffff9286`be8f7340 fffff803`b5a836fa     : ffffa085`2ebfa040 ffffa085`2ebfa040 fffff803`b5924aa0 ffffa085`005975e0 : nt!ExpWorkerThread+0x4bb
ffff9286`be8f74f0 fffff803`b5cad6c4     : ffffc081`4a2a8180 ffffa085`2ebfa040 fffff803`b5a836a0 c98ab88a`c38abb8a : nt!PspSystemThreadStartup+0x5a
ffff9286`be8f7540 00000000`00000000     : ffff9286`be8f8000 ffff9286`be8f1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x34


SYMBOL_NAME:  nt!RtlpHeapHandleError+40

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.26100.9168

STACK_COMMAND: .process /r /p 0xffffa085004d0040; .thread /r /p 0xffffa0852ebfa040 ; kb

BUCKET_ID_FUNC_OFFSET:  40

FAILURE_BUCKET_ID:  0x13a_17_nt!RtlpHeapHandleError

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {b1500314-0083-90bd-d812-716f3060523d}
Windows for home | Windows 11 | Devices and drivers
0 comments No comments

Answer accepted by question author

AI answer

2026-08-19T11:27:50.43+00:00

0x13A means the kernel heap manager detected heap corruption. In the dump, Arg1: 0x17 specifically means a block was corrupted in a delay free list, which is commonly associated with a use-after-free error or a buffer overflow of an adjacent block.

Since sfc, DISM, GPU driver reinstall, and a memory test were already tried, the next useful path is to focus on drivers and recent hardware/software changes rather than repeating those same steps.

Recommended steps:

  1. Check for recent driver or device changes
    • In Device Manager, look for any device with a warning icon.
    • Open the properties of recently updated or newly installed devices and review the device events.
    • Update or remove recently added drivers or system services.
    • This is especially important for storage, chipset, and other low-level device drivers.
  2. Check Event Viewer for related errors
    • Open Event Viewer and review the System log.
    • Look for critical or error events in the same time window as the blue screen.
    • The goal is to identify the device or driver active just before the crash.
  3. If hardware was recently changed, test that path
    • If any hardware was added or replaced, remove or reseat it if possible.
    • Check with the device manufacturer for updated firmware, BIOS, or driver packages.
    • For heap corruption after hardware changes, faulty or poorly seated hardware can be a trigger.
  4. Use Driver Verifier to expose a faulty driver
    • One accepted resolution for 0x13A cases that only show memory corruption is to enable Driver Verifier so Windows can force a more specific crash that identifies the bad driver.
    • Warning: Driver Verifier can make the system unstable or cause boot loops until it is disabled.
    • Before enabling it, create a restore point.
    • If Windows cannot boot afterward:
      1. Force shutdown during startup two or three times to enter Recovery.
      2. Go to Troubleshoot > Advanced Option > Startup Settings > Restart.
      3. Press 4 for Safe Mode.
      4. Open an elevated Command Prompt and run:
                verifier /reset
                verifier /bootmode resetonbootfail
        
  5. Run general stop-error checks that can still help
    • Run a virus scan.
    • Check disk/file-system health from File Explorer > drive Properties > Tools > Check.
    • If storage corruption is suspected, Chkdsk /f /r can detect and resolve structural file-system corruption. Warning: this requires a restart on the system partition.
  6. If the issue started after a specific driver update, roll back that driver
    • The dump shown does not identify a specific third-party driver.
    • In this situation, rolling back recently changed drivers is more useful than reinstalling random components.
  7. If another dump can be captured after Driver Verifier, compare multiple dumps
    • Microsoft guidance for corruption-style bug checks is to examine multiple dump files and look for the same code path or driver repeatedly.

The key point from the dump is that this is a heap corruption symptom, not proof that ntkrnlmp.exe itself is the root cause. The most likely next target is a faulty or incompatible driver, and Driver Verifier is the most direct next step when the dump only shows generic heap corruption.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Newest
  1. David-M 125.2K Reputation points Independent Advisor
    2026-08-19T12:02:19.7533333+00:00

    Hi. I'm David, and I'm happy to help you.


    The minidump you pasted does not mention any driver, only a generic system file.

    Was this the only minidump available? If you have more minidump files, share them. Sometimes, it may be necessary to analyze multiple minidumps to identify the cause of the problem.

    To make things easier, you can share the files themselves.

    These files are in C:\Windows\Minidump.

    (If you don't have a Minidump folder, check if it is in the plural Minidumps.)

    Copy any files you have to your desktop and store them in a ZIP file. Then, upload the ZIP file to the cloud (OneDrive), choose to share it, and get the link.

    Then, post the link to the ZIP file here so I can have a look.


    Looking forward to your reply.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.