From what plutoo was saying in the 34C3 panel, the PID vulnerability that defaults no PID to 0 is specific to 3.0.0, and was fixed in 3.0.1. He was asked what the differences between the earlier versions and 3.0 were, but did not address that part of the question.
I think it has to do with that...