Re: kernel which solves Intel security problem
For only 4 days now, Kernel 4.15-rc6 (release candidate 6) has the PIT (Page Isolation Table) stuff included. However, the default kernel configuration still has it disabled, so you would need to compile it yourself with CONFIG_PAGE_TABLE_ISOLATION=y (which I did yesterday). I believe it has also been backported to mainline kernel 4.11.13. I think it will still be awhile before Ubuntu kernels have this stuff.
Any follow-up information on your issue would be appreciated. Please have the courtesy to report back.