Ah, indeed, the "broken" one isn't even in the archive anymore, so there is nothing I can upgrade to:
$ apt-cache policy shim shim-signed shim: Installed: 15+1552672080.a4a1fbe-0ubuntu1 Candidate: 15+1552672080.a4a1fbe-0ubuntu1 Version table: *** 15+1552672080.a4a1fbe-0ubuntu1 100 100 /var/lib/dpkg/status 15+1533136590.3beb971-0ubuntu1 500 500 http://archive.ubuntu.com/ubuntu focal/main amd64 Packages shim-signed: Installed: 1.41+15+1552672080.a4a1fbe-0ubuntu1 Candidate: 1.41+15+1552672080.a4a1fbe-0ubuntu1 Version table: *** 1.41+15+1552672080.a4a1fbe-0ubuntu1 100 100 /var/lib/dpkg/status 1.40.3+15+1533136590.3beb971-0ubuntu1 500 500 http://archive.ubuntu.com/ubuntu focal/main amd64 Packages
Ah, indeed, the "broken" one isn't even in the archive anymore, so there is nothing I can upgrade to:
$ apt-cache policy shim shim-signed a4a1fbe- 0ubuntu1 a4a1fbe- 0ubuntu1 a4a1fbe- 0ubuntu1 100 dpkg/status 1533136590. 3beb971- 0ubuntu1 500 archive. ubuntu. com/ubuntu focal/main amd64 Packages 1552672080. a4a1fbe- 0ubuntu1 1552672080. a4a1fbe- 0ubuntu1 1552672080. a4a1fbe- 0ubuntu1 100 dpkg/status 40.3+15+ 1533136590. 3beb971- 0ubuntu1 500 archive. ubuntu. com/ubuntu focal/main amd64 Packages
shim:
Installed: 15+1552672080.
Candidate: 15+1552672080.
Version table:
*** 15+1552672080.
100 /var/lib/
15+
500 http://
shim-signed:
Installed: 1.41+15+
Candidate: 1.41+15+
Version table:
*** 1.41+15+
100 /var/lib/
1.
500 http://