I wonder if this could be avoided by writing the canonical implementations in Rust or better yet in some system with formal verification.
This is such a critical part of the software stack, that we need a more reliable way of validation than just a bunch of people staring at the code written in C.