[PATCH 6.15 232/480] mtd: fix possible integer overflow in erase_xfer()