The Debian Project team has announced that users of the Debian GNU/Linux 9 Stretch distribution should immediately upgrade their systems. The update updates the kernel by fixing two vulnerabilities.
The new Linux kernel security update reportedly addresses the CVE-2018-15471 discovered by Felix Wilhelm of Google Project Zero:
"Felix Wilhelm of Google Project Zero discovered a flaw in the hash handling of the xen-netback Linux kernel module. A malicious or buggy environment could allow access (usually with elevated privileges) to be denied service or information leaks," reads the security bulletin published by Salvatore Bonaccorso.
Of course, the Debian Project security team recommends that all users of the Debian GNU/Linux 9 Stretch distribution immediately update the kernel to version 4.9.110-3+deb9u6.
The update is already available in the main repositories of the distribution. So to upgrade the kernel, open a terminal and type the following command:
sudo apt-get update && sudo apt-get full-upgrade
The new version will replace last week's 4.9.110-3+deb9u5 kernel, which fixed 18 vulnerabilities.
____________________
