I've backported a number of fixes for security issues affecting 4.9- stable. All of these are already fixed in 4.14-stable and 4.19-stable.
Most of the issues involve filesystem validation, and I tested with the reproducers where available.
For the BPF fix, I verified that the self-tests (taken from 4.14) didn't regress and temporarily added logging to check that the mitigation is applied when needed.
Ben.