Actually, no. Stored Procedures can contain dynamic SQL, which is the actual problem, so it is quite possible to have a stored procedure with SQL Injection built into it. This would yield high-performance SQL Injection and little else.
The better answer is a parameterized query, which actually controls the inputs properly to ensure that no dynamic SQL is possible.