Corrected GCM counter incrementation to use only 32-bits instead of 128-bits Using 32-bits has the possibility to overwrite the IV in the first 12 bytes of the Y variable. Found by Yawning Angel