Fix size check in p25519 modular reduction

The check was meant to precisely catch an underflow.

Signed-off-by: Hanno Becker <hanno.becker@arm.com>
This commit is contained in:
Hanno Becker 2022-04-12 10:55:34 +01:00
parent 0235f7512f
commit 2ef0cff6c3

View File

@ -5223,7 +5223,7 @@ static int ecp_mod_p255( mbedtls_mpi *N )
/* Helper references for top part of N */
mbedtls_mpi_uint * const NT_p = N->p + P255_WIDTH;
const size_t NT_n = N->n - P255_WIDTH;
if( NT_n == 0 || NT_n > P255_WIDTH )
if( NT_n == 0 || NT_n > N->n )
return( 0 );
/* Split N as N + 2^256 M */