Home / Alt manpages / perl5381delta(1)

  • perl5381delta(1)
  • User command
  • linux

Check Perl 5.38.1 security coverage on Ubuntu

You will identify whether a Perl runtime is older than the 5.38.1 security release, record the package version that actually supplies it, and upgrade an Ubuntu installation when required. Allow about ten minutes for the checks, plus the time your package manager needs. The commands below were checked on a host running Perl 5.38.2 and Ubuntu packages 5.38.2-3.2ubuntu0.6.

This is an audit and package-maintenance guide, not an attempt to reproduce either vulnerability. Do not paste attacker-controlled regular expressions into a test program, and do not create a fake Windows cmd.exe to test the second issue.

1. Read what perl5381delta actually covers

The installed manual describes the differences between Perl 5.38.0 and 5.38.1. It names two security fixes: CVE-2023-47038, a one-byte heap buffer overflow triggered by a crafted regular expression using an illegal user-defined Unicode property, and CVE-2023-47039, a Windows path-search issue that could let an attacker supply cmd.exe from the current directory or another weakly controlled location.

The affected upstream range stated by the manual is Perl 5.30.0 through 5.38.0 for the Unicode-property issue. The Windows issue applies to Perl for Windows. A Linux host is not exposed to that Windows path-search behaviour, but its Perl runtime can still be too old for the first fix.

$ man perl5381delta
$ perl -e 'print "$^V\n"'
v5.38.2

Checkpoint: write down the runtime version and the operating system before changing packages. The perl5381delta page is release-specific, so do not treat its title as proof that the command installed on your host is exactly 5.38.1.

2. Check the interpreter selected by your shell

First confirm which executable runs when a script invokes perl. This matters on machines with a distribution Perl, a locally built Perl, and a version manager installed at the same time.

$ command -v perl
/usr/bin/perl
$ perl -e 'printf "perl=%s\n", $^V'
perl=v5.38.2
$ perl -e 'die "Perl is older than 5.38.1\n" unless $^V ge v5.38.1; print "Perl is at least 5.38.1\n"'
Perl is at least 5.38.1

The final check is a version comparison performed by Perl itself. It does not inspect a package database, and it says nothing about whether a different interpreter is hard-coded in a service unit or a script's shebang. If it fails, stop before running the application under that interpreter.

3. Match the runtime to its Debian package

On Ubuntu, use dpkg-query to see the installed packages and apt-cache policy to compare installed and candidate versions. These are read-only commands and do not need sudo.

$ dpkg-query -W -f='${Package} ${Version}\n' perl perl-doc
perl 5.38.2-3.2ubuntu0.6
perl-doc 5.38.2-3.2ubuntu0.6
$ apt-cache policy perl perl-doc
perl:
  Installed: 5.38.2-3.2ubuntu0.6
  Candidate: 5.38.2-3.2ubuntu0.6

Package revisions contain distribution suffixes, so compare the upstream runtime with perl -e and record the full Debian version separately. The perl-doc package supplies this manual; it is useful for reading the release notes but does not replace the perl interpreter package.

Checkpoint: if command -v perl points outside /usr/bin, check that installation separately. Upgrading Ubuntu's perl package may leave a locally installed interpreter unchanged.

4. Upgrade an affected Ubuntu installation

Only do this step during a suitable maintenance window. Package upgrades change files under system directories and can require dependent services or applications to restart later. Before proceeding, save your package and service change procedure, and make sure you can restore the machine from its normal snapshot or backup if the application does not start afterwards.

$ sudo apt-get update
$ sudo apt-get install --only-upgrade perl perl-doc

These are the commands that require elevated privileges. --only-upgrade avoids installing a package that is not already installed, while allowing its available update and required dependencies to be selected. Read the proposed changes before accepting them. If the candidate is still older than 5.38.1, do not force a version from an unrelated repository; fix the repository or support lifecycle issue through your normal Ubuntu process.

The example changes system state. If you need to abandon it before accepting the transaction, answer the package manager's confirmation prompt negatively. After an accepted upgrade, recovery is distribution-specific: consult /var/log/apt/history.log, the package cache, and your tested snapshot or rollback process rather than guessing a downgrade command.

5. Verify the result and the application boundary

Run the same checks again in the shell that will launch the application. A package transaction can succeed while a service still uses a virtual environment, a bundled Perl, or a fixed interpreter path.

$ command -v perl
/usr/bin/perl
$ perl -e 'printf "perl=%s\n", $^V; die "runtime too old\n" unless $^V ge v5.38.1'
perl=v5.38.2
$ dpkg-query -W -f='${Package} ${Version}\n' perl perl-doc
perl 5.38.2-3.2ubuntu0.6
perl-doc 5.38.2-3.2ubuntu0.6

For a service, inspect its configured executable without restarting it. Replace the placeholder with the real unit name:

$ systemctl cat YOUR-SERVICE.service | grep -E '^(ExecStart|Environment)='
$ systemctl show YOUR-SERVICE.service --property=ExecStart --no-pager

These inspection commands are read-only. Do not restart a production service solely because this guide says to do so. Schedule that action, check its rollback path, and then use the service's own health check and logs to confirm that it came back with the intended interpreter.

6. Keep the scope of the fix clear

Perl 5.38.1 fixes the two issues described in this delta document; it is not a general security audit of your Perl application or its CPAN dependencies. The manual also says to read perl5380delta when upgrading from an earlier development release, and points to Changes, INSTALL and README for other release and build details.

If you need to report a suspected Perl bug, the manual points to the Perl issue tracker. Do not put sensitive vulnerability details into a public issue. Use the private security contact process described by perlsec when public reporting would expose a working exploit.

Done means

  • The active perl executable and its version are recorded.
  • The runtime is at least Perl 5.38.1, or an upgrade is scheduled because it is older.
  • The Debian package version for both perl and perl-doc is recorded.
  • A locally installed or bundled Perl has not been mistaken for Ubuntu's package.
  • No crafted regular expression or fake Windows executable was used as a vulnerability test.
  • Any package or service change has a documented rollback path and an application-level health check.