Most likely as they have proven during the last 40 years, security is not in their agenda.
Even the Annex K design was misguided, as it expected parameters to still be separate pointer + length arguments, thus hardly changing anything regarding getting them wrong.