BIND 9 DNSSEC Validation Fails on new DS record
This is described in
"When a DS record for .COM is inserted into the root on 31 March 2011,
non-upgraded BIND 9 resolvers with DNSSEC validation enabled will have a
high probability of being unable to successfully resolve .COM names unless
they are restarted."
Probably merits an update in oldstable update 5.0.9.