No one is smart enough to write bug free in any language.
I can't find it now, but I heard that NASA developed processes to produce completely error-free code (for the moon landings iirc). The problem is that it's incredibly time consuming and expensive to do.
Like everything in CS, apparently this is a trade-off, not an absolute. You can get bug-free code, but it's not commercially viable and is extremely tedious to do.
Clearly it’s because people never got the memo: https://www.rfc-editor.org/rfc/rfc9225.html
That's why we designed better languages that can block the compilation if memory hasn't been handled properly.
The difference is that C casually makes common everyday bugs into security vulnerabilities.
This is the reason why performant and "safe" systems languages are on the rise and being accepted into foundational areas of our operating systems (such as the kernel). When the attack defense surface is tighter (language, tooling, compiler instead of the actual code itself), the smart folks can stay at that layer, while the masses can write more code at a level of abstraction that nullifies many of these vulnerabilities by default.