In the Linux kernel, the following vulnerability has been resolved:
md: raid1: fix potential OOB in raid1removedisk()
If rddev->raiddisk is greater than mddev->raiddisks, there will be an out-of-bounds in raid1removedisk(). We have already found similar reports as follows:
1) commit d17f744e883b ("md-raid10: fix KASAN warning") 2) commit 1ebc2cec0b7d ("dm raid: fix KASAN warning in raid5removedisk")
Fix this bug by checking whether the "number" variable is valid.