Use perl5362delta to Check Perl 5.36.2 Security Fixes
You will finish with a quick, reproducible way to read the installed Perl 5.36.2 release notes and check whether the interpreter you are about to use is in the affected version range. The local manual describes two security fixes: a heap buffer overflow in crafted regular expressions and a Windows search-path problem involving cmd.exe.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell and Perl's documentation package. The commands below are read-only and normally need no elevated privileges. They inspect documentation and report versions; they do not upgrade Perl, edit configuration or restart a service.
1. Confirm which Perl is in use
Start with the interpreter that your shell will find. This avoids a common trap: checking one Perl installation and then running a script with another one from a different path, virtual environment or service account.
$ command -v perl
/usr/bin/perl
$ perl -V:version
version='5.38.2';
$ perl -e 'printf "running Perl %vd\n", $^V'
running Perl 5.38.2
The path and version are machine-specific. The useful checkpoint is the final version line, not the example value. Keep the check in the same shell, container or service environment as the application you are assessing.
2. Check that the delta document is installed
perl5362delta is a documentation page, not a separate program to execute. The perldoc -l form prints the file that supplies the page:
$ perldoc -l perl5362delta
/usr/share/perl/5.38/pod/perl5362delta.pod
If that command says the page cannot be found, check the package that supplies Perl documentation through your normal package manager. On this host the installed package is perl-doc, version 5.38.2-3.2ubuntu0.6. Do not infer the interpreter version from the documentation package alone: run the version check in step 1 as well.
Checkpoint: make sure the path printed by perldoc -l is readable and that the interpreter and documentation come from the environment you intend to audit.
3. Read the documented release boundary
Open the page through the normal manual interface:
$ man perl5362delta
The page covers differences between Perl 5.36.1 and 5.36.2. If your starting point is 5.36.0, it explicitly directs you to read perl5361delta first. That is a scope boundary, not a recommendation to skip intermediate release notes when you are investigating a longer upgrade path.
For a short, searchable view of the security section, use a pipeline that does not alter the manual:
$ man perl5362delta | col -b | sed -n '/^Security$/,/^Acknowledgements$/p'
Security
This release fixes the following security issues.
CVE-2023-47038 - Write past buffer end via illegal user-defined Unicode
property
CVE-2023-47039 - Perl for Windows binary hijacking vulnerability
Exact wrapping can vary with the terminal and installed manual renderer. The checkpoint is that both CVE headings appear. If your output differs, use the full page rather than treating a truncated pipeline as proof that a section is absent.
4. Understand the first security fix
CVE-2023-47038 concerns a crafted regular expression compiled by Perl 5.30.0 through 5.38.0. The manual describes a one-byte, attacker-controlled write past the end of a heap-allocated buffer, reached through an illegal user-defined Unicode property.
This is a version-range finding, not a claim that every regular expression is unsafe. It matters when an application compiles expressions influenced by an untrusted user or by untrusted data. A read-only version check cannot prove that an application is exploitable, and the delta page does not replace a review of how that application builds and compiles patterns.
If the interpreter reported in step 1 is in the affected range, record that fact for the person or process responsible for patching the host. Avoid trying to solve it by removing one expression from a production application unless you have an assessed workaround. The durable action is to obtain a supported Perl update through your normal change process, then rerun the same version check.
5. Understand the Windows-only fix
CVE-2023-47039 is a Perl for Windows binary hijacking issue. The manual explains that Windows Perl searches for cmd.exe using the system path, but initially looks in the current working directory. An attacker who can place a malicious cmd.exe in a weakly protected location could cause an administrator to execute arbitrary code when running a Windows Perl executable from a compromised location.
This particular path-search behaviour does not describe a Linux execution, but it still belongs in an upgrade review when the same Perl code or tooling runs on Windows. Do not copy a Linux conclusion across platforms: record the operating system alongside the Perl version and assess Windows launch locations separately.
For a Linux host, the useful result is narrower: this page still documents the release, but the Windows-specific CVE is not a Linux path-search finding. That distinction prevents an accurate advisory from turning into an inaccurate local diagnosis.
6. Recheck after an approved update
Updating Perl can affect several interpreters at once, so verify the actual executable again after the change. Run the commands as the same account and from the same environment as the application:
$ command -v perl
$ perl -V:version
$ perl -e 'printf "running Perl %vd\n", $^V'
running Perl 5.36.2
The example's version is only illustrative. A later vendor-supported release may be preferable, and the manual page itself does not define a universal safe version for every distribution. What matters here is that your recorded interpreter is no longer in the vulnerable range described by the page, or that the owner has documented why a compensating control and an upgrade plan are acceptable.
Do not delete the old interpreter or alter a service's shebang as an unplanned shortcut. Those changes can break system tools and are difficult to undo during an incident. If an update changed a service, use that service's normal rollback procedure and confirm its executable path before declaring the check complete.
Done means
- You checked the exact
perlexecutable and version used by the workload. perldoc -l perl5362deltalocated the installed release-note source.- You read the 5.36.1 to 5.36.2 boundary and followed the earlier delta when starting from 5.36.0.
- You recorded CVE-2023-47038 as the crafted-regex buffer-overflow issue.
- You treated CVE-2023-47039 as a Windows Perl path-search issue, not a Linux finding.
- After any approved update, you repeated the version check in the application's real environment.