KVM: VMX: Don't rely _only_ on CPUID to enforce XCR0 restrictions for ECREATE