The problem is that the word “virus” is not of any technical significance. The way I see it there are two important classes of malicious software:
1) The class that relies on being executed normally by the user, but then does things contrary to what the user expected it to.
2) The class that actually exploits design oversights to be able to run with privileges, or run at all, when it was not intended to by the user.
The latter class is obviously of a significantly larger concern.
“GNU/Linux” is also a social buzzword bereft of any technical meaning. Nothing exists that deserves to be so grouped together under “GNU/Linux” for any technical reasons, and the exploitations that class 2 exploits often have nothing to do with it.
There recently was such an exploit that allowed malicious code to be executed ex nihilō. More specifically, it relied on an indexing dæmon that ran in the background and indexed media files, by creating a specifically crafted malformed image file, it could trick this dæmon into executing arbitrary code, apparently even as root as the dæmon ran as root and was shared between all users as I read it.
Such exploits are not a “GNU/Linux” issue; they are an issue of whatever system has this dæmon both installed and running. Apparently Fedora had, but my system does not.
The majority of such escalations these days seem to have little to do with either GNU or Linux, and mostly seemed to exploit “Freedesktop”, which is known to favor copying certain design sensibilities from Windows and with it the kind of escalative holes that such design sensibilities often bring with them, such as the aforementioned.