and even then to do any serious damage they need the root user password.
Not strictly true unless you're talking about servers - yes, damage to the system itself is restricted but most desktop users wouldn't care as much about those as to the personal files in their home directory - which would, of course, be theoretically vulnerable.
But, as you say, linux viruses are exceptionally rare, so it's not a big worry ...
Peter.