The "KeyTrap" DNS vulnerability
DNS resolvers (those that handle DNSSEC, at least) are almost uniformly
vulnerable to an exploit
that has been named "KeyTrap". In short, the right type of packet can
send a DNS system into something close to an infinite loop, taking it out
of service indefinitely.