Perl 5.38.2: Check the Security Fixes and Verify Your Upgrade
You will finish with a quick, reproducible check that the Perl interpreter on a Linux host is at version 5.38.2 or later, and that you understand the two security fixes documented for Perl 5.38.2. The local reference is perl5382delta, the release note for the change from 5.38.0 to 5.38.2.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell and permission to read the installed package database. Updating packages normally requires elevated privileges, but every check in this guide is unprivileged. The examples were checked on a Debian-family system with Perl 5.38.2 and the perl-doc package installed.
1. Check the interpreter you will actually run
Start with the executable selected by your shell. This avoids checking one Perl binary and running another later:
$ command -v perl
/usr/bin/perl
$ perl -e 'print "$^V\n"'
v5.38.2
The version must come from the interpreter, not from a directory name or an assumption about the distribution. If command -v prints a user-managed path, inspect that installation separately before deciding that the host is patched.
Checkpoint: record the exact version and path. On this host, the matching package query is:
$ dpkg-query -W -f='${Package} ${Version}\n' perl perl-doc
perl 5.38.2-3.2ubuntu0.6
perl-doc 5.38.2-3.2ubuntu0.6
Package revisions vary, so your output will not necessarily match the example. The useful facts are the package name, the distribution revision and the interpreter version. If the package database reports 5.38.0 while perl -e reports another version, stop and resolve the path or package mismatch before updating.
2. Read the local release note
Read the installed copy rather than relying on a search result. It is supplied by perl-doc and describes Perl 5.38.2 as the change from 5.38.0. It explicitly skips 5.38.1, which was a short-lived broken release:
$ man perl5382delta
$ zcat /usr/share/man/man1/perl5382delta.1.gz | sed -n '/^\.SH Security/,/^\.SH Acknowledgements/p'
The first command is easier to read interactively. The second is useful when you need a plain-text extract for an audit note. The compressed file is documentation, not an executable script. Do not pipe it to a shell or treat text from it as a command.
Checkpoint: the release note should identify CVE-2023-47038 and CVE-2023-47039 under its Security heading. If man cannot find the page, install or repair perl-doc through your normal package process. That is an administrative change and may require sudo; reading the file does not.
3. Understand what 5.38.2 fixes
CVE-2023-47038 affects a crafted regular expression containing an illegal user-defined Unicode property. The release note says that Perl 5.30.0 through 5.38.0 could write one attacker-controlled byte beyond a heap buffer when compiling such an expression. This is a reason to keep the interpreter patched even if your application does not deliberately use custom Unicode properties: regular expressions can be reached through input-processing code and third-party modules.
CVE-2023-47039 concerns Perl for Windows. A Windows Perl executable could search for cmd.exe in the current working directory before safer locations. An attacker who could place a malicious file in a weakly protected location could cause arbitrary code execution when an administrator launched Perl from there. This issue is not a Linux execution path, but it still matters if the same software estate includes Windows workstations, build agents or administrators' laptops.
Do not try to reproduce either vulnerability on a production host. The purpose of this guide is to verify the installed version and package state, not to compile hostile regular expressions or place executables in searched directories.
4. Update through the package manager when needed
If your interpreter is older than 5.38.2, or your distribution marks the installed package as vulnerable, use the normal security-update workflow for that distribution. On Ubuntu or Debian, an administrator might review available updates like this:
$ apt-cache policy perl perl-doc
$ apt list --upgradable 2>/dev/null | grep -E '^(perl|perl-doc)/'
These commands only inspect package metadata. Applying an update changes system files and may affect services that embed Perl, so schedule it according to your host's maintenance process and keep a tested recovery path. Do not paste a version copied from another distribution into an apt command. Let the configured repositories select the supported revision.
When an update is approved, the administrative form is distribution-specific. For a Debian-family host it is commonly:
$ sudo apt update
$ sudo apt install --only-upgrade perl perl-doc
Review the proposed package list before accepting it. If the transaction fails, leave the existing installation intact and investigate the package-manager error. If it succeeds but a long-running service still reports the old interpreter, restart only that service during its maintenance window, then verify its runtime separately. Do not reboot or restart unrelated services merely because Perl was updated.
5. Verify after the change
Open a new shell or use the service's real execution context, then repeat the interpreter check:
$ command -v perl
/usr/bin/perl
$ perl -e 'printf "perl=%s\n", $^V'
perl=v5.38.2
$ perl -MConfig -e 'printf "arch=%s\n", $Config{archname}'
arch=x86_64-linux-gnu
The architecture line is a useful sanity check when a host has multiple Perl installations. It does not replace the version check. For an application or service, verify the command it actually starts, because a virtual environment, wrapper or hard-coded interpreter path can select a different binary.
Verify that the documentation now agrees with the interpreter:
$ perldoc -l perl5382delta
/usr/share/perl/5.38/pod/perl5382delta.pod
$ perl -e 'die "old Perl\n" if $] < 5.038002; print "Perl version is in range\n"'
Perl version is in range
The numeric comparison is a local gate for Perl 5.38.2 and later. It does not claim that every later Perl release has identical behaviour, nor does it replace your distribution's security advisory process.
6. Keep the result auditable
Save the command output, package revision and update transaction identifier in the host's normal change record. Include which Perl paths were checked and whether Windows systems were in scope. If you discover an older copy later, undo the ambiguity by removing it from the relevant service or shell configuration through your normal change process, then repeat the checks. Do not delete a Perl installation while another application may depend on it.
Done means
command -v perlandperl -eidentify the interpreter used by the check.- The interpreter is Perl 5.38.2 or later, with its package revision recorded.
- The local
perl5382deltapage was read and both documented CVEs were understood. - Any update was reviewed and applied through the distribution's package manager, with a recovery path.
- Application or service contexts were checked separately where they may use another Perl binary.