Thanks Peter. I agree that memory corruption / overwrite of the register save in a lower call frame is the most likely cause.
I will keep digging. Ida is a great idea to go find the callee that uses R14.
BTW, I think that KeAcquireSpinLock *is* KeAcquireSpinLockRaiseToDpc in this case. Us network guys rarely get into obscure kernel and executive areas ???
Cheers,
Dave Cattley