VMware's virtualization software (ESXi, Workstation, Fusion) has the concept of "CPUID masks", which can be used to mask off features to the guest from the host's CPU for this kind of work. Since it is a very advanced concept, we didn't expose it in the UI for Workstation or Fusion, but the VMX shipped with both products should support it as far as I know (I don't think we've ever disabled that feature for a product anyhow). If you dig into the menus you can set the flag values on ESXi, as sometimes for fleets we have admins that want to normalize their CPU flags across all of their virtual hardware (I believe this was very popular when the NX-bit was new).
However, you're not at a lost for the desktop products. Editing the [vm-name].vmx file and adding the lines to control the cpuid registers is a pretty simple endeavor; the lines are formatted 'cpuid.<cpuid-in>.<GPR> = "value"', and value should contain the mask for the whole 32-bit register, with a dash '-' for no special processing of this flag, "h" for using the host's setting of this flag, '0' for explicit disabling the flag, or '1' for explicit enabling the flag. For example:
cpuid.7.ebx = "--------------------0-----------"
disables the (if I counted correctly) 20th bit from the return of CPUID in the ebx register when CPUID is passed in '7' as a parameter to eax, which should correspond to disabling the SMAP CPUID flag.(The VMX file is a bit non-obvious to get to on macOS, as we use 'packages' to make VMs nicer to handle, but simply right clicking the package and selecting "show package contents" should reveal the VMX file.)
[takes off VMware hat].