If you look at the Xen vulnerabilities there has been a good split between flaws in the hypervisor/host kernel, and flaws in the QEMU device model. sVirt doesn't claim to protect the kernel, but it does offer valuable protection against QEMU device model flaws.