> as it had basically never had any major security vulnerabilities in its entire existence.
This link[0] shows a CVE with CVSS of 9.8 in 2015 (and a handful of smaller ones). From this other page on the same site[1], it claims that all of all 5 of the CVE's are caused by overflow or memory corruption.
[0] https://www.cvedetails.com/vulnerability-list/vendor_id-72/p...
[1] https://www.cvedetails.com/product/5075/GNU-Coreutils.html?v...