The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone...
Vulnerability
Vulners
Apply vendor security patch