Do SSDs use CTR mode? How does one perform a padding oracle against an SSD? I feel like we're pretty far away from the relevant context, which is users corrupting data on an SSD.
There is no documented way to read cyphertext. I am SURE some manufacturer specific commands exist. But they will likely be undocumented, model-specific, and may be locked away behind a manufacturer key
"Please explain how you'll mutate a single bit of output given only input"
Same way Rowhammer works. Exploiting a physical vulnerability gives zero damns about encryption. Now whether you get VALID or USABLE data from the attack is an entirely different story.