Crash in textshaping, Analyzed 2 dumps, total processed 37, rate equals 5.41%



Top 1: Version = v1.7224.1005.626, Total count = 2


dump count = 1

ChildEBP RetAddr  
0488e1d4 5f0a2631 TextShaping!ApplyFeatures+0x32
0488e258 5f08ee2d TextShaping!SubstituteOtlGlyphs+0x181
0488e280 5f08af9b TextShaping!ShapingLibraryInternal::SubstituteOtlGlyphsWithFallback+0x1d
0488e51c 5f07d826 TextShaping!GenericEngineGetGlyphs+0x79b
0488e5e8 77530766 TextShaping!ShapingGetGlyphs+0x356
0488e71c 7752fc18 gdi32full!ShlShapeOT+0x1c6
0488e770 7752eb99 gdi32full!ScriptShape+0x148
0488e7e8 7752e2c9 gdi32full!RenderItemNoFallback+0x5f9
0488e820 7752e188 gdi32full!RenderItemWithFallback+0x119
0488e848 7752df0e gdi32full!RenderItem+0x28
0488e8a0 7752b2c8 gdi32full!ScriptStringAnalyzeGlyphs+0x1be
0488ed04 7752a68f gdi32full!ScriptStringAnalyse+0x738
0488eebc 77529ee0 gdi32full!LpkCharsetDraw+0x60f
0488eee8 767ad4fd gdi32full!LpkDrawTextEx+0x30
0488ef44 767ad394 user32!DT_DrawStr+0x5f
0488efa4 767acecb user32!DT_GetLineBreak+0xa2
0488f074 767accce user32!DrawTextExWorker+0x1f9
0488f090 7102e6ca user32!DrawTextExW+0x1e
0488f0f4 7102dd34 uxtheme!CTextDraw::GetTextExtent+0xa4
0488f13c 710243c9 uxtheme!GetThemeTextExtent+0x74
0488f190 71030f87 uxtheme!_GetNcCaptionTextSize+0x61
0488f280 7103293c uxtheme!CThemeWnd::GetNcWindowMetrics+0x307
0488f32c 710329ef uxtheme!_WindowPosChangedWorker+0x7c
0488f338 7102f545 uxtheme!OnOwpPostWindowPosChanged+0x1f
0488f388 767b7f43 uxtheme!ThemePostWndProc+0x355
0488f474 767b7b30 user32!UserCallWinProcCheckWow+0x363
0488f4d8 767bf897 user32!DispatchClientMessage+0x190
0488f518 776a56cd user32!__fnINLPWINDOWPOS+0x37
0488f568 7104d44f ntdll!KiUserCallbackDispatcher+0x4d
0488f594 710300ef uxtheme!OnOwpPreDwmCompositionChanged+0x4f
0488f5f0 767b7eef uxtheme!ThemePreWndProc+0x43f
0488f6dc 767b67c0 user32!UserCallWinProcCheckWow+0x30f
0488f758 767b62f0 user32!DispatchMessageWorker+0x4c0
0488f764 79c70bc1 user32!DispatchMessageW+0x10
0488f788 79c70a7b AcMgr!WTL::CMessageLoop::Run+0xc1
0488f7e4 79c7477f AcMgr!CPopMgrTrayClient::Process+0x8b
0488f7f0 79d23f20 AcMgr!CThread::ThreadProc+0x1f
0488f82c 7647fcc9 AcMgr!thread_start<unsigned int (__stdcall*)(void *)>+0x57
0488f83c 776982ae kernel32!BaseThreadInitThunk+0x19
0488f898 7769827e ntdll!__RtlUserThreadStart+0x2f
0488f8a8 00000000 ntdll!_RtlUserThreadStart+0x1b
03162fb6fda4204570a3a751249933a4_000.dmp

dump count = 1

ChildEBP RetAddr  
053ae194 70761b71 TextShaping!ApplyFeatures+0x32
053ae218 7074e36d TextShaping!SubstituteOtlGlyphs+0x181
053ae240 7074a4db TextShaping!ShapingLibraryInternal::SubstituteOtlGlyphsWithFallback+0x1d
053ae4dc 7073cd76 TextShaping!GenericEngineGetGlyphs+0x79b
053ae5a8 764a06e6 TextShaping!ShapingGetGlyphs+0x356
053ae6dc 7649fb98 gdi32full!ShlShapeOT+0x1c6
053ae730 7649eb39 gdi32full!ScriptShape+0x148
053ae7a8 7649e269 gdi32full!RenderItemNoFallback+0x5f9
053ae7e0 7649e128 gdi32full!RenderItemWithFallback+0x119
053ae808 7649deae gdi32full!RenderItem+0x28
053ae860 7649b268 gdi32full!ScriptStringAnalyzeGlyphs+0x1be
053aecc4 7649a63f gdi32full!ScriptStringAnalyse+0x738
053aee3c 7649aa68 gdi32full!LpkCharsetDraw+0x60f
053aef08 764a2982 gdi32full!GetTextMetricsW+0x108
053aef3c 765bcb2b gdi32full!IntersectClipRectImpl+0x42
053af00c 765bc92e user32!DrawTextExWorker+0x1f9
053af028 70d1e6ca user32!DrawTextExW+0x1e
053af08c 70d1dd34 uxtheme!CTextDraw::GetTextExtent+0xa4
053af0d4 70d143c9 uxtheme!GetThemeTextExtent+0x74
053af128 70d20f87 uxtheme!_GetNcCaptionTextSize+0x61
053af218 70d2293c uxtheme!CThemeWnd::GetNcWindowMetrics+0x307
053af2c4 70d229ef uxtheme!_WindowPosChangedWorker+0x7c
053af2d0 70d1f545 uxtheme!OnOwpPostWindowPosChanged+0x1f
053af320 765c7ba3 uxtheme!ThemePostWndProc+0x355
053af40c 765c7790 user32!UserCallWinProcCheckWow+0x363
053af470 765cf4f7 user32!DispatchClientMessage+0x190
053af4b0 77d956cd user32!__fnINLPWINDOWPOS+0x37
053af500 7673124c ntdll!KiUserCallbackDispatcher+0x4d
053af504 70d3d44f win32u!NtUserSetWindowPos+0xc
053af530 70d200ef uxtheme!OnOwpPreDwmCompositionChanged+0x4f
053af58c 765c7b4f uxtheme!ThemePreWndProc+0x43f
053af678 765c6420 user32!UserCallWinProcCheckWow+0x30f
053af6f4 765c5f50 user32!DispatchMessageWorker+0x4c0
053af700 7959f5a1 user32!DispatchMessageW+0x10
053af724 7959f2f7 CfgRelayEx!WTL::CMessageLoop::Run+0xc1
053af784 795a196f CfgRelayEx!CConfigCenterStub::Process+0xa7
053af790 795bffcb CfgRelayEx!CThread::ThreadProc+0x1f
053af7cc 7769fcc9 CfgRelayEx!thread_start<unsigned int (__stdcall*)(void *)>+0x57
053af7dc 77d882ae kernel32!BaseThreadInitThunk+0x19
053af838 77d8827e ntdll!__RtlUserThreadStart+0x2f
053af848 00000000 ntdll!_RtlUserThreadStart+0x1b
ecb9caa6454862028370b94f4d6fa99f_000.dmp