@amszmidt But nobody is saying that's not true.
When I say we analyze this problem from a practical perspective is the following: think about a modern C program. You need a compiler to build it, say GCC.
You distro gives you a compiled version of that software claiming it is free. How can you know it is free? You can only blindly trust your distro...
If your distro's maintainers act with good faith, it may still happen their compiler is corrupt. How do you know if it is?