Merge "Backport overlay security fix" into oc-dev