Fix size check in p25519 modular reduction

The check was meant to precisely catch an underflow.

Signed-off-by: Hanno Becker <hanno.becker@arm.com>
diff --git a/library/ecp_curves.c b/library/ecp_curves.c
index 718d0d0..d3a14d6 100644
--- a/library/ecp_curves.c
+++ b/library/ecp_curves.c
@@ -5223,7 +5223,7 @@
     /* Helper references for top part of N */
     mbedtls_mpi_uint * const NT_p = N->p + P255_WIDTH;
     const size_t NT_n = N->n - P255_WIDTH;
-    if( NT_n == 0 || NT_n > P255_WIDTH )
+    if( NT_n == 0 || NT_n > N->n )
         return( 0 );
 
     /* Split N as N + 2^256 M */