Welcome to Microsoft Q&A Platform, thanks for posting your query here.
Firstly, apologies for the delay in responding here and any inconvenience this issue may have caused.
AKS has a mechanism called "surge nodes" which is the "spare" nodes that AKS automatically provision during upgrade. In this scenario when upgrade is triggered, AKS scales up by 1 for a surge node to balance the pod workload, which causes problem.
How this is used and how CNI IP address need to be calculated is documented here. The surge node mechanism is documented here.
Hope this helps.
If you need further help on this, tag me in a comment.
If the suggested response helped you resolve your issue, please 'Accept as answer', so that it can help others in the community looking for help on similar topics.