In the Linux kernel, the following vulnerability has been resolved: md: raid1: fix potential OOB in raid1removedisk() If rddev->raiddisk is greater than mddev->raiddisks, there will be an out-of-bounds in raid1removedisk(). We have already found similar reports as follows: 1) commit d17f744e883b ("md-raid10: fix KASAN warning") 2) commit 1ebc2cec0b7d ("dm raid: fix KASAN warning in raid5removedisk") Fix this bug by checking whether the "number" variable is valid.