Certainly the string library, of all places, should be using secure code.
I'm sure there are sooo many people running Linux on pre-OSX Mac harddrives formatted with HFS that could be hacked with a buffer overflow.
Are you seriously arguing that buffer overflows in the kernel are not a big deal?