GHSA-qhj8-q5r6-8q6j
GitHub Security Advisory
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
In matrix-sdk-base before 0.14.1, calling the `RoomMember::normalized_power_level()` method can cause a panic if a room member has a power level of `Int::Min`.
### Patches
The issue is fixed in matrix-sdk-base 0.14.1.
### Workarounds
The affected method isn’t used internally, so avoiding calling `RoomMember::normalized_power_level()` prevents the panic.
Affected Packages
crates.io
matrix-sdk-base
Affected versions:
0
(fixed in 0.14.1)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: September 18, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.