Backport f79936545fb12 ("x86/sev-es: Allow copy_from_kernel_nofault() in earlier boot")