Unlike doing this through the GUI, this seems to retain the root password and prevent this vuln from re-occuring.
I've tested both approaches - disabling via the GUI causes this bug to re-occur next time you try, disabling via the shell does not.
My hope in recommending people disable this way is that with the additional scrutiny on this subsystem, accounts disabled this way will remain genuinely disabled in a future update. Either way this doesn't seem to reintroduce the bug.
... but the whole thing is a mess overall.
To be flippant, I might say HN discussions seem to QA using Apple methods.
sudo passwd -u root
It's sad we have to do this, though.
/System/Library/CoreServices/Applications/Directory Utility.app
Edit > Change Root Password
Anyone who does this should probably set a password for now and then disable the root user account once it has been patched.