Thanks, Michael.
My system is a remote host, and I'm in the process of a reinstall on one.
If I correctly read the links you sent, the latest kernel has that CVE covered.
But another remote host seems to have the same problem. Each host comes from a different provider and had slightly different default pinnings in '/etc/apt/sources.list'.
I'll double-check my pinnings.