What does BSOD 58 (SYSTEM_UNWIND_PREVIOUS_USER) mean?

 
Could be also:
ConstantTypeOS
ERROR_BAD_NET_RESPWin32 errorWindows
EDEADLOCKerrnoLinux
ESHUTDOWNerrnoMac
EOWNERDEADerrnoSolaris
Previous Next
SYSTEM_EXIT_OWNED_MUTEX SYSTEM_SERVICE_EXCEPTION

SYSTEM_UNWIND_PREVIOUS_USER

Invalid unwind across user/kernel context for SYSTEM_UNWIND_PREVIOUS_USER

SYSTEM_UNWIND_PREVIOUS_USER is bug check code 0x0000003A. This bug check belongs to exception and stack-unwind handling. It indicates that control-flow or stack metadata did not match the expected transition between user and kernel contexts.

How to read it in a dump

  • Inspect trap frames, exception records, and stack frames around the transition.
  • Stack corruption, bad callback return, or code that damaged unwind state can be more important than the stop code itself.
  • A full dump helps distinguish user callback damage from kernel stack corruption.

What to check

  • Use WinDbg to examine the trap frame and call stack manually, not only !analyze output.
  • Check drivers using callbacks, system calls, or user-mode upcalls.
  • Look for memory corruption or overwritten return addresses.

References

Dump evidence

Preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “this result”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.

Analysis order

  • Run WinDbg !analyze -v, then inspect the documented meaning of each parameter instead of relying only on the probably-caused-by line.
  • find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with system / unwind / previous / user.
  • keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.

Do not repeatedly reboot a machine affected by this result before collecting the dump and event logs. Recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.


Looking for a different code? Search another status or error code.