In RPyC before 6.0.0, when a server exposes a method that calls the attribute named array for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.
{ "binaries": [ { "binary_version": "3.4.4-1", "binary_name": "python3-rpyc" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-27758.json"
{ "binaries": [ { "binary_version": "5.0.1-3", "binary_name": "python3-rpyc" } ] }
{ "binaries": [ { "binary_version": "5.3.1-1", "binary_name": "python3-rpyc" } ] }
{ "binaries": [ { "binary_version": "6.0.1-1", "binary_name": "python3-rpyc" } ] }