Upstream commit f7c90c2aa4004808dff777ba6ae2c7294dd06851 ("x86/xen: don't write ptes directly in 32-bit PV guests") should be considered for stable kernels from 4.14 up (I'll send backports for older kernels when I know you are taking the patch). The patch avoids 32-bit Xen PV guests creating intermediate L1TF vulnerable PTEs. Juergen