Last I looked, plenty of fixes were trickling into the kernel in 2014. I wonder how many of those made the long backport to stable.
Let alone all those 2.6 kernels (and older!) in the wild. And all your 32-bit devices are probably gonna have a bad time.
Various libc choices in use probably have time_t signed.
In [1]: import datetime
In [2]: datetime.datetime.utcfromtimestamp(2**31)
Out[2]: datetime.datetime(2038, 1, 19, 3, 14, 8)Nervous nellies worried about rollover, and insisting we switch to 64-bit timestamps everywhere, are a nuisance. You can keep one 64-bit epoch, such as boot time or most recent foreign attack on NYC, and as many 32-bit offsets from that as you like, and always be able to get a 64-bit time whenever you need it. Most often you only need a difference, so one epoch is as good as any, and you can work purely in 32 bits.
Pcap format is good until 2106 assuming the 1970 epoch. A bit of one of the now-unused header fields could be repurposed to indicate another.