Kernel memory leak in rtp1.sys / rtp2.sys still present in F-Secure 26.8 (driver 1.1.2607.9217) – pr

Daimer
Daimer Posts: 1 New Member

Hi,I can confirm the kernel pool leak reported earlier in this thread. It is still present in F-Secure 26.8 on my machine, with the same rtp1.sys / rtp2.sys binaries mentioned by the previous reporter.

ENVIRONMENT

  • Windows 11 Home 25H2, build 26200.9457
  • AMD Ryzen 7 5800X, 32 GB RAM
  • F-Secure 26.8
  • rtp1.sys and rtp2.sys 1.1.2607.9217 (Avira real-time protection filter driver)
  • BdSentry.sys 3.0.2412.1247, BdNet.sys 1.0.2411.1743, nif_driver_64.sys (fsnifdrv) 3.0.35

WORKLOAD
Software development workstation running an automated build and test loop around the clock (Git for Windows / MSYS2 bash, Node.js, npm builds, headless Chrome tests). This creates a very large number of short-lived processes.

MEASUREMENTS (last boot 2026-09-30 19:22)

  1. Leaked process objects
    • 2026-10-01 14:55: performance counter \Objects\Processes = 140,865, while only 386 processes were actually running (Get-Process).
    • 2026-10-01 15:20: \Objects\Processes = 144,170, still 386 running processes.
      The number of process objects in the kernel grows with every process that is started, but they are never freed after the process exits.
  2. Commit charge (commit limit 42.2 GB)
    • 2026-10-01 04:30: 27.3 GB
    • 2026-10-01 14:55: 34.3 GB
    • 2026-10-01 15:20: 36.6 GB
      That is roughly +0.7 GB per hour under this workload.
  3. Kernel pools over the same period
    • Paged pool: 2.16 GB -> 4.00 GB
    • Nonpaged pool: 1.20 GB -> 1.88 GB
  4. Not caused by user-mode processes
    • Total private bytes of all processes stayed flat at about 15.5 GB.
    • Per-process pool usage (\Process()\Pool Paged Bytes and \Process()\Pool Nonpaged Bytes) sums to only about 0.1 GB.
      The growth is entirely kernel-side.

IMPACT

  • On 2026-10-01 at about 03:22 the commit limit was reached and applications started failing ("VirtualProtect failed with code 0x5af").
  • This machine has had three unexpected shutdowns (Kernel-Power 41 / Event 6008) on 2026-09-18, 2026-09-22 and 2026-09-28. All of them happened during heavy overnight build activity, so I suspect they are related, although Ihave not proven this.
  • The only workaround I have found is rebooting the machine regularly.

HOW TO SEE IT
Run anything that starts many short-lived processes, for example a build loop or "for /l %i in (1,1,10000) do cmd /c exit". Then compare the \Objects\Processes performance counter with the number of running processes. Thecounter keeps growing, while the number of running processes stays the same. This matches the earlier analysis in this thread: the real-time protection driver appears to take a reference on every created process and neverreleases it.

QUESTIONS

  1. Is a fix for rtp1.sys / rtp2.sys scheduled, and is there an estimated release version or date?
  2. Is there a supported workaround that avoids the leak until then, for example excluding specific processes or folders from real-time scanning?

I am happy to provide an FSDIAG report or poolmon snapshots if that helps the engineering team.

Thank you.