diff --git a/crates/matrix-sdk-base/RUSTSEC-2025-0000.md b/crates/matrix-sdk-base/RUSTSEC-2025-0000.md new file mode 100644 index 00000000..3fc0e111 --- /dev/null +++ b/crates/matrix-sdk-base/RUSTSEC-2025-0000.md @@ -0,0 +1,20 @@ +```toml +[advisory] +id = "RUSTSEC-2025-0000" +package = "matrix-sdk-base" +date = "2025-09-11" +url = "https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-qhj8-q5r6-8q6j" +aliases = ["CVE-2025-59047", "GHSA-qhj8-q5r6-8q6j"] + +[affected.functions] +"matrix_sdk_base::RoomMember::normalized_power_level" = ["<= 0.14.0"] + +[versions] +patched = [">= 0.14.1"] +``` + +# matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method + +In matrix-sdk-base before 0.14.1, calling the +`RoomMember::normalized_power_level()` method can cause a panic if a room member +has a power level of `Int::Min`.