update Xen page-table isolation (XPTI) mitigation
and add Branch Target Injection (BTI) mitigation for XSA-254
DoS via non-preemptable L3/L4 pagetable freeing [XSA-252] (#1549568)
grant table v2 -> v1 transition may crash Xen [XSA-255] (#1549570)
x86 PVH guest without LAPIC may DoS the host [XSA-256] (#1549572)