i use 2.9.27 version and i am recentrly facing some issues.
i see cpu 100% and when i run torch, one of my wan interfaces shows too many connections from 2 specific ips and different ports to local 53 port.
After i drop input of those 2 ips, in torch i see the same behaviour.
I have disabled remote dns requests but not fixed.
I think torch shows the packets because the are send to you.
It is regardless of what the firewall does with the received packages.
I assume you are being used as an DNS relay.
Post your ip firewall filter output so we can assist you in blocking unwanted traffic