According to https://gcc.gnu.org/onlinedocs/gcc/Instrumentation-Options.html, it seems that the "-fstack-protector-strong" flag is only needed for SECURITY_CFLAGS in meta/conf/distro/include/security_flags.inc, and there's no need to add it to SECURITY_LDFLAGS and SECURITY_X_LDFLAGS.
Agreed, the docs state: "Emit extra code to check for buffer overflows, such as stack smashing attacks. This is done by adding a guard variable to functions with vulnerable objects." Emitting extra code is certainly a compiler, not linker, option.
Patch sent to oe-core list: http://lists.openembedded.org/pipermail/openembedded-core/2016-August/125369.html
There was some concern about dropping this and its presence doesn't appear to be causing issues. As we don't have a lot of bandwidth to fully test the ramifications of this on multiple toolchains and multiple layers I'm closing this as WONTFIX. If you believe there's an issue with continuing to include this option in SECURITY*LDFLAGS please reopen this bug and we'll try to find resources in a future cycle.