There's a conflict between stability and security here. Debian stable probably will be updated to raise the default mmap_min_addr, but we need to clearly announce the change so that users that need DOS/Win16 compatibility know that they need to override it.