Fix size check in p25519 modular reduction
The check was meant to precisely catch an underflow.
Signed-off-by: Hanno Becker <hanno.becker@arm.com>
diff --git a/library/ecp_curves.c b/library/ecp_curves.c
index 718d0d0..d3a14d6 100644
--- a/library/ecp_curves.c
+++ b/library/ecp_curves.c
@@ -5223,7 +5223,7 @@
/* Helper references for top part of N */
mbedtls_mpi_uint * const NT_p = N->p + P255_WIDTH;
const size_t NT_n = N->n - P255_WIDTH;
- if( NT_n == 0 || NT_n > P255_WIDTH )
+ if( NT_n == 0 || NT_n > N->n )
return( 0 );
/* Split N as N + 2^256 M */