Home / Alt manpages / perl5281delta(1)

  • perl5281delta(1)
  • User command
  • linux

Read the Perl 5.28.1 Delta Safely on Linux

You will finish with a short, reproducible way to inspect what Perl 5.28.1 changed from Perl 5.28.0, identify the two security fixes recorded there, and avoid treating an old release note as proof that the Perl installed on your host is patched. The examples use the perl5281delta(1) manpage installed by Ubuntu's perl-doc package.

Allow about ten minutes. You need a shell, the man command and access to the installed Perl documentation. The inspection is read-only and needs no elevated privileges. Do not use this guide as a substitute for your distribution's current security notices or package updates.

1. Check the Perl version and documentation package

Start by recording the interpreter you are actually running. This separates the host's current Perl from the historical version described by the manpage:

$ perl -v | sed -n '1,5p'

This is perl 5, version 38, subversion 2 (v5.38.2) built for x86_64-linux-gnu-thread-multi
(with 67 registered patches, see perl -V for more detail)

$ dpkg-query -W -f='${Package} ${Version}\n' perl perl-base perl-doc
perl 5.38.2-3.2ubuntu0.6
perl-base 5.38.2-3.2ubuntu0.6
perl-doc 5.38.2-3.2ubuntu0.6

Your package revision will differ. The useful comparison is the major and minor interpreter version, not just the fact that the documentation package is installed.

Checkpoint

If you expected a Perl 5.28 interpreter but the first command reports 5.38.2, you are reviewing historical compatibility and security information, not auditing the running binary's exact patch level.

2. Confirm that perl5281delta is a manpage

The name looks like a program, but this package provides documentation rather than an executable called perl5281delta. Ask man where it found the page:

$ man -w perl5281delta
/usr/share/man/man1/perl5281delta.1.gz
$ command -v perl5281delta
$

An empty command -v result is expected here. Do not try to run the name as a command, and do not add sudo merely because it is listed in section 1. Reading a compressed manpage is an ordinary user operation.

If man -w reports that no manual entry exists, install the documentation package supplied by your distribution, then repeat the check. On this host the installed package is perl-doc; package names and versions are distribution-specific.

3. Read the release boundary first

Render the page without the terminal formatting so that its headings and text can be searched or captured in a review note:

$ man -P cat perl5281delta | sed -n '1,35p'
PERL5281DELTA(1)       Perl Programmers Reference Guide       PERL5281DELTA(1)

NAME
       perl5281delta - what is new for perl v5.28.1

DESCRIPTION
       This document describes differences between the 5.28.0 release and the
       5.28.1 release.

The scope is the first useful fact: this is a delta between two Perl releases. If you are upgrading from 5.26, the page itself points you to perl5280delta first. If you are investigating a modern distribution package, move from this page to the distribution's package changelog and security advisory.

Checkpoint

Write down both versions before interpreting a fix. "Fixed in 5.28.1" does not mean "fixed in every later package", and the local page does not tell you whether your installed package has received a backport.

4. Review the two security entries

Search for the security section and inspect its two CVE headings:

$ man -P cat perl5281delta | sed -n '/^ *Security$/,/^ *Incompatible Changes$/p'
Security
   [CVE-2018-18311] Integer overflow leading to buffer overflow and
       segmentation fault
   [CVE-2018-18312] Heap-buffer-overflow write in S_regatom (regcomp.c)

The first entry describes integer arithmetic in Perl_my_setenv() wrapping when an environment variable name and value together approached 0x7fffffff. Attacker-controlled data could then lead to a write beyond the allocated buffer. The second says that a crafted regular expression could trigger a heap-buffer-overflow during compilation, with possible arbitrary code execution.

These descriptions establish why the release matters, but they do not establish exploitability in your application or the patch state of your host. Follow the issue links from the page when you need historical implementation detail: CVE-2018-18311 issue and CVE-2018-18312 issue.

Do not reproduce a suspected overflow or run an untrusted regular expression as a "test" on a production system. The safe verification here is reading the release note and checking package metadata.

5. Check compatibility and ordinary bug fixes

Before planning an upgrade, inspect the incompatible-changes and selected-fixes sections:

$ man -P cat perl5281delta | sed -n '/^ *Incompatible Changes$/,/^ *Modules and Pragmata$/p'
Incompatible Changes
       There are no changes intentionally incompatible with 5.28.0.

$ man -P cat perl5281delta | sed -n '/^ *Selected Bug Fixes$/,/^ *Acknowledgements$/p'

The page records no intentionally incompatible changes between 5.28.0 and 5.28.1. It also records an index() optimisation warning fix inside a when clause, a correction to decimal-digit matching in script runs, and an in-place editing change that stops leaking directory handles. The GitHub references for the first and third fixes are GH #16626 and GH #16602.

"No intentionally incompatible changes" is a compatibility statement, not a test result. Run your own application's test suite, check its CPAN dependencies, and review the distribution's packaging policy before changing the interpreter.

6. Verify what the page cannot tell you

Use the manpage as an index into a patch review, not as a live vulnerability scanner. For a real host check, record the package version, repository source and applicable distribution security updates. A useful local evidence bundle is:

$ perl -V:version -V:api_versionstring
version='5.38.2';
api_versionstring='5.38.0';
$ dpkg-query -W -f='${Package} ${Version}\n' perl-base perl-doc
perl-base 5.38.2-3.2ubuntu0.6
perl-doc 5.38.2-3.2ubuntu0.6

The exact fields and package revision vary. Keep the output with the review ticket, then compare it with your operating system vendor's advisory. Do not infer that a newer-looking version is safe for a particular CVE without checking the vendor's backport notes.

The final "Give Thanks" section contains perlthanks, which sends email to Perl porters. Do not run it as part of this inspection: it changes external state and is unrelated to verifying the release delta.

Done means

  • You recorded the installed Perl and perl-doc package versions.
  • You confirmed that perl5281delta is a manpage, not an executable.
  • You identified the two documented security fixes and their upstream issue links.
  • You checked the compatibility statement and selected bug-fix notes.
  • You separated historical release information from the current host's patch status.
  • You made no system, service, interpreter or external-email changes.