[PATCH 5.10 122/523] mtd: fix possible integer overflow in erase_xfer()