CRITICAL_STRUCTURE_CORRUPTION (0x109): what it means and how to fix it
Updated Oct 9, 2026 · Checked against Microsoft documentation · How this page is made
Quick answer
CRITICAL_STRUCTURE_CORRUPTION (0x00000109) indicates that Windows detected unauthorized changes or data corruption inside protected kernel code. It is most often caused by a faulty third-party driver attempting to patch kernel memory, or by failing physical RAM. Testing your system memory and checking the Windows Event Viewer for offending drivers are the best first steps.
What it means
Windows bug check 0x00000109 signals that the operating system kernel discovered that critical internal code or data structures have been modified. Windows maintains strict safeguards over its core memory areas. On 64-bit systems and versions dating back to Windows Server 2003 with Service Pack 1 (SP1), the operating system explicitly prohibits kernel patching, allowing modifications only through authorized Microsoft-originated hot patches.
Why the Stop Code Triggers
When Windows boots, critical components such as processor tables, process lists, driver dispatch routines, and system service functions are loaded into protected kernel space. The kernel actively validates the integrity of these areas. If code or data in one of these structures changes unexpectedly, Windows triggers bug check 0x109 immediately to prevent data corruption or total operating system instability.
The Role of Bug Check Parameters
A crash screen displaying 0x00000109 includes four diagnostic parameters. The fourth parameter (Parameter 4) is the most informative. It defines the exact type of memory region or structure that suffered corruption. Microsoft defines dozens of values for Parameter 4, including:
- 0x0 or 0x20: A generic data region
- 0x1: A function modification
- 0x2: A processor interrupt dispatch table (IDT)
- 0x3: A processor global descriptor table (GDT)
- 0x4, 0x5, 0x1A, or 0x1B: Process list corruptions
- 0xA: Modification of a system service function
- 0x12: Driver call dispatcher modification
- 0x1C: Driver object corruption
- 0x102: Modification of win32k.sys
Underlying Mechanisms
Three primary events cause this crash. First, a driver may attempt to modify protected structures, either accidentally due to a bug or deliberately to alter operating system behavior. Second, physical hardware failure can silently alter bits in memory where kernel structures are cached. Third, software developers attempting to debug the kernel may trigger this stop code if normal breakpoints (bp) are set without having the kernel debugger attached at system startup.
Common causes
- A third-party device driver inadvertently or deliberately modified protected kernel code or structures.
- Failing physical memory (RAM) corrupted kernel code or data stored in memory modules.
- A developer set a normal kernel breakpoint (bp) without attaching the debugger at system boot.
- Newly installed hardware is incompatible with the installed Windows operating system version.
How to fix it
Safest and most likely fixes first. Readers' answers to "Did this fix it?" reorder this list over time.
Test memory with Windows Memory Diagnostics
Use this first to verify whether bad RAM modules are corrupting kernel data in memory.
- Open the search box in Control Panel, type Memory, and select Diagnose your computer's memory problems.
- Choose the option to restart immediately and check for problems.
- Allow the diagnostic utility to complete its scan before Windows reboots.
- Open Event Viewer after Windows loads.
- Navigate to Windows Logs, click System, and search for the MemoryDiagnostics-Results entry to review the outcome.
Did this fix it?Check the System log in Event Viewer for faulty drivers
Use this to identify which driver or device is triggering the kernel corruption.
- Open Event Viewer by searching for it in the Start menu.
- Expand the Windows Logs folder on the left pane and select System.
- Look for error events timestamped immediately before the crash.
- Review the event details to find specific device names or system files mentioned in the logs.
Did this fix it?Update or disable the faulting driver
Use this if Event Viewer or the crash screen identifies a specific device driver file.
- Visit the official website of the hardware or software manufacturer responsible for the driver.
- Download and install the latest compatible driver package for your Windows version.
- If no update is available and crashes persist, open Device Manager.
- Locate the problem device, right-click it, and select Disable device to stop the driver from loading.
Did this fix it?Run manufacturer hardware diagnostics
Use this if memory scans pass clean but hardware defects are still suspected.
- Restart your computer and access the pre-boot menu using the hardware manufacturer's diagnostic key (such as F12, F2, or Esc).
- Select the onboard hardware diagnostic suite provided by the PC manufacturer.
- Run an extended test on the motherboard, processor, and connected storage components.
- Replace or reseat any component that fails the diagnostics.
Did this fix it?
Is it just you?
25+ Microsoft Q&A threads discuss this. Most recent activity:
- Critical Structure CorruptionOct 14, 2021
- BSOD | ANALYSIS_INCONCLUSIVE | CRITICAL_STRUCTURE_CORRUPTIONOct 10, 2021
- Critical Structure Corruption (tcpip.sys) BSOD on Windows 10Jan 18, 2021
- lxcore.sys BSOD, windows 11 build 22621.1265Apr 6, 2023
- Windows BSOD - Critical Structure CorruptionOct 18, 2023
Checked Oct 8, 2026. Refreshed automatically every few days.
Sources
Frequently asked questions
What does Parameter 4 mean in a 0x109 crash?
Parameter 4 defines the specific corrupted region, such as a process list, an interrupt dispatch table, a system service function, or win32k.sys.
Can bad RAM cause CRITICAL_STRUCTURE_CORRUPTION?
Yes. If physical RAM fails or develops bad sectors, kernel code and protected data held in that memory can become corrupted, triggering bug check 0x109.
Can software developers cause bug check 0x109 during debugging?
Yes. Setting normal kernel breakpoints (bp) causes this stop code if the debugger was not attached at system boot time, whereas processor breakpoints (ba) can be set at any time.