What does BSOD 22 (CID_HANDLE_CREATION) mean?

 
Could be also:
ConstantTypeOS
ERROR_BAD_COMMANDWin32 errorWindows
KERN_INVALID_HOSTKern returnMac
ippStsNoIppFunctionFoundIntel Ipp StatusAny
EINVALerrnoAny
Previous Next
LAST_CHANCE_CALLED_FROM_KMODE CID_HANDLE_DELETION

CID_HANDLE_CREATION

Process/thread client ID handle creation failure for CID_HANDLE_CREATION

CID_HANDLE_CREATION is bug check code 0x00000016. Client IDs identify processes and threads. This bug check points at a failure or corruption path while the kernel creates the handle bookkeeping for a process or thread identity.

How to read it in a dump for CID_HANDLE_CREATION

  • The relevant objects are process and thread executive structures, handle tables, and security callbacks.
  • Do not diagnose it as a normal CreateProcess or CreateThread failure unless the dump shows that path.
  • Pool corruption or callback-driver interference can be more important than the numeric argument values.

What to check for CID_HANDLE_CREATION

  • Check process/thread notification callbacks and security products.
  • Inspect handle table and object manager state in the dump.
  • Enable verifier for drivers that monitor process creation or inject callbacks.

References for CID_HANDLE_CREATION

Dump evidence for CID_HANDLE_CREATION

For CID_HANDLE_CREATION, preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “CID_HANDLE_CREATION”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.

Analysis order for CID_HANDLE_CREATION

  • Run WinDbg !analyze -v, then inspect the documented meaning of each CID_HANDLE_CREATION parameter instead of relying only on the probably-caused-by line.
  • For CID_HANDLE_CREATION, find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with cid / handle / creation.
  • For CID_HANDLE_CREATION, keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.

Do not repeatedly reboot a machine affected by CID_HANDLE_CREATION before collecting the dump and event logs. For CID_HANDLE_CREATION, recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.

Dump evidence for CID_HANDLE_CREATION

For CID_HANDLE_CREATION, preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “CID_HANDLE_CREATION”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.

Analysis order for CID_HANDLE_CREATION

  • Run WinDbg !analyze -v, then inspect the documented meaning of each CID_HANDLE_CREATION parameter instead of relying only on the probably-caused-by line.
  • For CID_HANDLE_CREATION, find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with cid / handle / creation.
  • For CID_HANDLE_CREATION, keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.

Do not repeatedly reboot a machine affected by CID_HANDLE_CREATION before collecting the dump and event logs. For CID_HANDLE_CREATION, recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.


Looking for a different code? Search another status or error code.