{"id":"DEBIAN-CVE-2022-49613","details":"In the Linux kernel, the following vulnerability has been resolved:  serial: 8250: Fix PM usage_count for console handover  When console is enabled, univ8250_console_setup() calls serial8250_console_setup() before .dev is set to uart_port. Therefore, it will not call pm_runtime_get_sync(). Later, when the actual driver is going to take over univ8250_console_exit() is called. As .dev is already set, serial8250_console_exit() makes pm_runtime_put_sync() call with usage count being zero triggering PM usage count warning (extra debug for univ8250_console_setup(), univ8250_console_exit(), and serial8250_register_ports()):  [    0.068987] univ8250_console_setup ttyS0 nodev [    0.499670] printk: console [ttyS0] enabled [    0.717955] printk: console [ttyS0] printing thread started [    1.960163] serial8250_register_ports assigned dev for ttyS0 [    1.976830] printk: console [ttyS0] disabled [    1.976888] printk: console [ttyS0] printing thread stopped [    1.977073] univ8250_console_exit ttyS0 usage:0 [    1.977075] serial8250 serial8250: Runtime PM usage count underflow! [    1.977429] dw-apb-uart.6: ttyS0 at MMIO 0x4010006000 (irq = 33, base_baud = 115200) is a 16550A [    1.977812] univ8250_console_setup ttyS0 usage:2 [    1.978167] printk: console [ttyS0] printing thread started [    1.978203] printk: console [ttyS0] enabled  To fix the issue, call pm_runtime_get_sync() in serial8250_register_ports() as soon as .dev is set for an uart_port if it has console enabled.  This problem became apparent only recently because 82586a721595 (\"PM: runtime: Avoid device usage count underflows\") added the warning printout. I confirmed this problem also occurs with v5.18 (w/o the warning printout, obviously).","modified":"2026-09-01T16:04:35.922886068Z","published":"2025-02-26T07:01:36.747Z","upstream":["CVE-2022-49613"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49613"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49613.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49613.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49613.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}