@Suiseiseki Depends on your threat model. You're talking about the operating system, but @bugaevc's points all apply to Linux-libre's kernel.
Proprietary userland tends to be malware, but proprietary OEM software tends to just be buggy and unauditable. If you consider proprietary software to be inherently malicious, then your CPU (with its proprietary firmware and proprietary logic circuitry) is malicious and GNU Linux-libre is insecure.