This is related to the same CVE fixes in PR #75845 The CVEs are in the dependencies of ip-masq-agent - debian-base bump at: https://github.com/kubernetes-incubator/ip-masq-agent/pull/31 debian-iptables-amd64 bump at: https://github.com/kubernetes-incubator/ip-masq-agent/pull/30