DEVICE_ATTR_SEC_REH_RO(sr, SR_PROG_MAGIC, SR_PROG_ADDR, SR_REH_ADDR);
 DEVICE_ATTR_SEC_REH_RO(pr, PR_PROG_MAGIC, PR_PROG_ADDR, PR_REH_ADDR);
 
+#define FLASH_COUNT_SIZE 4096  /* count stored as inverted bit vector */
+
+static ssize_t flash_count_show(struct device *dev,
+                               struct device_attribute *attr, char *buf)
+{
+       struct m10bmc_sec *sec = dev_get_drvdata(dev);
+       unsigned int stride, num_bits;
+       u8 *flash_buf;
+       int cnt, ret;
+
+       stride = regmap_get_reg_stride(sec->m10bmc->regmap);
+       num_bits = FLASH_COUNT_SIZE * 8;
+
+       flash_buf = kmalloc(FLASH_COUNT_SIZE, GFP_KERNEL);
+       if (!flash_buf)
+               return -ENOMEM;
+
+       if (FLASH_COUNT_SIZE % stride) {
+               dev_err(sec->dev,
+                       "FLASH_COUNT_SIZE (0x%x) not aligned to stride (0x%x)\n",
+                       FLASH_COUNT_SIZE, stride);
+               WARN_ON_ONCE(1);
+               return -EINVAL;
+       }
+
+       ret = regmap_bulk_read(sec->m10bmc->regmap, STAGING_FLASH_COUNT,
+                              flash_buf, FLASH_COUNT_SIZE / stride);
+       if (ret) {
+               dev_err(sec->dev,
+                       "failed to read flash count: %x cnt %x: %d\n",
+                       STAGING_FLASH_COUNT, FLASH_COUNT_SIZE / stride, ret);
+               goto exit_free;
+       }
+       cnt = num_bits - bitmap_weight((unsigned long *)flash_buf, num_bits);
+
+exit_free:
+       kfree(flash_buf);
+
+       return ret ? : sysfs_emit(buf, "%u\n", cnt);
+}
+static DEVICE_ATTR_RO(flash_count);
+
 static struct attribute *m10bmc_security_attrs[] = {
+       &dev_attr_flash_count.attr,
        &dev_attr_bmc_root_entry_hash.attr,
        &dev_attr_sr_root_entry_hash.attr,
        &dev_attr_pr_root_entry_hash.attr,