[PATCH 5.4 107/403] mtd: fix possible integer overflow in erase_xfer()