[PATCH 6.12 160/369] mtd: fix possible integer overflow in erase_xfer()