This is a checker-found bug. In c2_intr.c:handle_vq, the variable reply_msg can be NULL (line 152), but is dereferenced unconditionally (line 177).
Still same in the git tree...Can you please post this to the lkml? Thanks.
No, sorry. I don't do kernel stuff at the moment.
I will post a patch to Roland.