new file mode 100644
@@ -0,0 +1,36 @@
+From 9d412e4715b17404b5e4c6d9f0d2b5c1a100aa74 Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Tue, 30 Jun 2026 00:11:50 +0200
+Subject: [PATCH 2/9] avformat/spdifenc: bound DTS core_size against the packet
+ size in the HD path
+
+Fixes: out of array read
+Fixes: yBSax492UIB9
+Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64833
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/spdifenc.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c
+index ab3f73d..16eebda 100644
+--- a/libavformat/spdifenc.c
++++ b/libavformat/spdifenc.c
+@@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket *pkt, int core_size,
+ * (dtshd_fallback == 0) */
+ ctx->dtshd_skip = 1;
+ }
+- if (ctx->dtshd_skip && core_size) {
++ if (ctx->dtshd_skip && core_size && core_size <= pkt->size) {
+ pkt_size = core_size;
+ if (ctx->dtshd_fallback >= 0)
+ --ctx->dtshd_skip;
+--
+2.43.0
+
@@ -27,6 +27,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
file://0001-ffbuild-commonmak-Consolidate-pattern-rules-for-comp.patch \
file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \
file://CVE-2026-64830.patch \
+ file://CVE-2026-64833.patch \
"
SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"