A BIND 9 DNS server set up to be a caching resolver is vulnerable to a user querying a domain with very large resource record sets (RRSets) when trying to negatively cache a response. This can cause the BIND 9 DNS server (named process) to crash.
When an authoritative server processes a successful IXFR transfer or a
dynamic update, there is a small window of time during which the IXFR/update coupled with a query may cause a deadlock to occur.