DISM /ScanHealth leaks WinSxS\Temp\InFlight data on Windows 11 25H2 Build 26200.9457

David Itzcovich 0 Reputation points
2026-09-20T13:46:31.82+00:00

Running routine DISM component store maintenance on Windows 11 25H2,

Build 26200.9457 (KB5129195), after KB5124008 (Build 26200.9445).

BUG: DISM /Online /Cleanup-Image /ScanHealth permanently leaks staging

data into C:\Windows\WinSxS\Temp\InFlight on every run. Never reclaimed

by StartComponentCleanup, /ResetBase, RestoreHealth, or

RevertPendingActions + reboot. AnalyzeComponentStore's "Cache and

Temporary Data" never returns to 0 bytes; grew to 1.3 GB before I

traced the cause.

EXACT REPRO (confirmed twice, back-to-back, nothing else in between):

  1. Run ScanHealth. InFlight = 196.76 MB
  2. Run ScanHealth again, no other activity. InFlight = 393.52 MB Exactly 2.0000x the prior value. Fully reproducible.

CBS.log indicates the growth occurs during the CheckCsi phase. Each ScanHealth run performs CSI metadata refresh operations and opens 163,386 files:

"Direct SIL provider: Number of files opened: 163386"

"CSI Store Metadata refreshed: True"

163K files get opened/compared and CSI metadata rebuilt, but the

resulting InFlight staging data is never torn down.

ONLY WORKAROUND: stop TrustedInstaller / confirm no TiWorker.exe

running, then takeown /R + icacls /grant Administrators:F /T + delete

InFlight's contents manually. Verified safe - sfc /scannow and

ScanHealth/CheckHealth report clean before and after, same scan

duration.

Expected: ScanHealth should not leave persistent staging data behind.

Cache/Temp should return to ~0 bytes after cleanup, as on prior builds.

Windows for home | Windows 11 | Files, folders, and storage

2 answers

Sort by: Oldest
  1. David Itzcovich 0 Reputation points
    2026-09-20T14:03:47.2833333+00:00

    Proposed workaround as powershell script to clean cache until this issue is fixed,

    # =========================================================================
    # CHECK CBS/TrustedInstaller IS IDLE, THEN TAKE OWNERSHIP AND CLEAR InFlight
    # Run this AFTER a reboot, once you've confirmed cache growth (>500MB) persists
    # =========================================================================
    # --- 1. Confirm TrustedInstaller service is stopped ---
    $tiService = Get-Service TrustedInstaller
    Write-Host "TrustedInstaller service status: $($tiService.Status)" -ForegroundColor Cyan
    if ($tiService.Status -ne 'Stopped') {
        Write-Host "TrustedInstaller is still running. Waiting 2 minutes and rechecking..." -ForegroundColor Yellow
        Start-Sleep -Seconds 120
        $tiService = Get-Service TrustedInstaller
        Write-Host "Rechecked status: $($tiService.Status)" -ForegroundColor Cyan
    }
    # --- 2. Confirm no TiWorker process is active ---
    $tiWorker = Get-Process TiWorker -ErrorAction SilentlyContinue
    if ($tiWorker) {
        Write-Host "TiWorker is still running (PID $($tiWorker.Id), StartTime $($tiWorker.StartTime)). Not safe to proceed." -ForegroundColor Red
        return
    } else {
        Write-Host "TiWorker not running. Confirmed idle." -ForegroundColor Green
    }
    # --- 3. Only proceed if TrustedInstaller is stopped ---
    if ($tiService.Status -eq 'Stopped') {
        Write-Host "`nSystem is idle. Proceeding with InFlight cleanup." -ForegroundColor Cyan
        # Take ownership of InFlight and everything inside it
        takeown /F "C:\Windows\WinSxS\Temp\InFlight" /R /D Y
        # Grant Administrators full control
        icacls "C:\Windows\WinSxS\Temp\InFlight" /grant Administrators:F /T /C
        # Delete contents (folder itself remains, only contents removed)
        Get-ChildItem "C:\Windows\WinSxS\Temp\InFlight" -Force | Remove-Item -Recurse -Force -ErrorAction Stop
        # Verify
        $remaining = Get-ChildItem "C:\Windows\WinSxS\Temp\InFlight" -Recurse -Force -ErrorAction SilentlyContinue |
            Measure-Object -Property Length -Sum
        Write-Host "`nRemaining size in InFlight: $([math]::Round($remaining.Sum / 1MB, 2)) MB" -ForegroundColor Green
        # Confirm system health afterward
        Write-Host "`nRunning SFC to confirm nothing was disturbed..." -ForegroundColor Cyan
        sfc /scannow
    } else {
        Write-Host "`nTrustedInstaller still not stopped after wait. Aborting - do not proceed manually until it's idle." -ForegroundColor Red
    }
    

    Was this answer helpful?


  2. CrazyKats 19,840 Reputation points Volunteer Moderator
    2026-09-20T14:21:43.6433333+00:00

    Hi David,

    Please make sure to file this

    issue in the Feedback Hub so

    the Engineering team gets the data.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.