New versions of BIND 9 are available from https://www.isc.org/downloads - https://downloads.isc.org/isc/bind9/9.18.33/patches/ - https://downloads.isc.org/isc/bind9/9.20.5/patches/ - https://downloads.isc.org/isc/bind9/9.21.4/patches/
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1910 to the following vulnerability:
A BIND 9 DNS server set up to be a caching resolver is vulnerable to a user querying a domain with very large resource record sets (RRSets) when trying to negatively cache a response. This can cause the BIND 9 DNS server (named process) to crash.
http://www.isc.org/software/bind/advisories/cve-2011-1910