What does BSOD 21 (LAST_CHANCE_CALLED_FROM_KMODE) mean?

 
Could be also:
ConstantTypeOS
ERROR_NOT_READYWin32 errorWindows
KERN_RIGHT_EXISTSKern returnMac
ippStsCpuMismatchIntel Ipp StatusAny
EISDIRerrnoAny
Previous Next
CREATE_DELETE_LOCK_NOT_LOCKED CID_HANDLE_CREATION

LAST_CHANCE_CALLED_FROM_KMODE

Unhandled kernel-mode exception escalation for LAST_CHANCE_CALLED_FROM_KMODE

LAST_CHANCE_CALLED_FROM_KMODE is bug check code 0x00000015. This bug check means kernel-mode exception handling reached a point where the exception could not be recovered. The failing instruction, exception record, and module on the stack are more useful than the name alone.

How to read it in a dump

  • Inspect the exception code, trap frame, and faulting instruction.
  • Separate software exceptions from access violations, illegal instructions, stack corruption, or execute-protection failures.
  • If a driver is on the stack, preserve symbols and module version information.

What to check

  • Run WinDbg !analyze -v and inspect the exception/trap frames.
  • Check recently updated drivers and kernel hooks.
  • Use Driver Verifier if the same driver repeatedly appears before the last-chance path.

References

Dump evidence

Preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “this result”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.

Analysis order

  • Run WinDbg !analyze -v, then inspect the documented meaning of each parameter instead of relying only on the probably-caused-by line.
  • find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with last / chance / called / from / kmode.
  • keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.

Do not repeatedly reboot a machine affected by this result before collecting the dump and event logs. Recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.


Looking for a different code? Search another status or error code.